Improper authentication in Ray - CVE-2025-62593
Published: December 11, 2025 / Updated: August 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper authentication implemented on "/api/jobs" and "/api/job_agent/jobs/" endpoints. A remote attacker can trick the victim into visiting a malicious website and force the victim's browser into sending a crafted payload to the affected endpoints available at the developer's machine, resulting in remote code execution.
Affected software
Red Hat OpenShift AI (RHOAI)
AI Inference Server
How to mitigate CVE-2025-62593
Red Hat OpenShift AI (RHOAI) - update to 2.25.1
AI Inference Server - update to 3.2.5