A security vulnerability has been identified in Ray, a development tool used by many people building applications and online services. This is a code injection flaw, which means an unauthorized attacker could potentially run harmful code on systems that use the tool, a risk referred to as remote code execution.
The issue can be exploited when accessing content through Firefox or Safari web browsers, so any developers using Ray as part of their workflow may be exposed to this risk if they use these browsers while working with the tool.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2025-62593