preloader

· · devops digital-security ai mlops cve vulnerability-management europe cisa-kev

CISA Just Put a Two-Year-Old AI Framework Bug on Its Must-Patch List. If Your Data Science Team Runs Ray, That Is Not a Coincidence

Source: CISA

Most CISA Known Exploited Vulnerabilities additions are old news dressed up as a deadline. This one is different because of where it lives: not a firewall, not a web server, but Ray, the open-source compute engine that a huge share of the industry now uses to train and serve AI models at scale.

A defence that was never a defence

CVE-2025-62593 sits in Ray’s HTTP API, the interface a developer’s browser uses to talk to a running Ray dashboard or job server. The only check standing between an unauthenticated request and code execution was whether the request’s User-Agent header started with the string “Mozilla”. That is not a security control, it is a formality, because the fetch API lets any webpage set its own User-Agent value. Combine that with a DNS rebinding attack, which tricks a browser into believing an attacker-controlled server and a private, local Ray instance are the same origin, and a developer does not need to click anything malicious or type a password wrong. Visiting the wrong webpage in Firefox or Safari while Ray is running nearby is enough. The fix landed in Ray 2.52.0; anything earlier is exposed.

The sequel to a campaign security teams already know

This is not Ray’s first appearance in vulnerability research. In 2024, researchers uncovered ShadowRay, a mass exploitation campaign that found thousands of Ray clusters sitting on the open internet with no authentication configured at all, many of them already compromised for cryptocurrency mining, stolen cloud credentials and hijacked GPU capacity. CVE-2025-62593 is a different vector, it does not require an exposed dashboard, only a browser and a network path, but it lands on the same underlying pattern: AI compute infrastructure is being built and deployed faster than it is being secured, and attackers have noticed.

Why this matters more in Europe than the CVSS score suggests

European organisations building AI features increasingly run Ray and similar frameworks on self-hosted or EU-region infrastructure specifically to keep training data under GDPR-compliant control rather than routing it through a third-party managed API. That instinct is sound, but it also means the security burden for that infrastructure sits entirely with the internal team running it, not a vendor’s shared responsibility model. A data science group that stood up a Ray cluster to hit a project deadline rarely has the same patch discipline as the DevOps team managing production web infrastructure, and this vulnerability is exactly the kind of gap that falls through that difference.

If your organisation runs Ray, or any self-hosted AI or MLOps stack, and you are not certain what is reachable from an ordinary employee’s browser, contact Excello Digital. We help European businesses bring the same patch discipline and network segmentation to their AI infrastructure that they already expect from the rest of their DevOps stack.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!