#VU119863 Improper authentication in Ray - CVE-2025-62593
Published: December 11, 2025
Ray
Anyscale
Description
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to improper authentication implemented on "/api/jobs" and "/api/job_agent/jobs/" endpoints. A remote attacker can trick the victim into visiting a malicious website and force the victim's browser into sending a crafted payload to the affected endpoints available at the developer's machine, resulting in remote code execution.