A security vulnerability has been discovered in Ray-Project Ray, a popular development tool used by teams to build and test applications. This is a code injection flaw, which means an attacker could potentially run unauthorized, malicious code on any system that has this tool installed. Developers who use Ray as part of their development workflow may be exposed to this risk.
The vulnerability can be exploited remotely, so an attacker does not need physical access to a system to carry out an attack. Reports confirm this flaw can be triggered when users access the Ray tool via Firefox or Safari web browsers.
Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2025-62593