A security flaw has been found in Ray-Project Ray, a development tool many web creators use to build and test their projects. This is a code injection vulnerability, meaning attackers could exploit it to run their own harmful code remotely on any system where the Ray tool is running. The flaw can be triggered when accessing Ray through the Firefox or Safari web browsers, so developers who use Ray for work are at risk of their systems being compromised if they use those browsers with the tool.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2025-62593