Skip to content

Security1 publisher3 min readPublished

CVE-2025-62593: A Ray Developer's Browser Is Now the Attack Surface

Ray never authenticated its job endpoints, and the User-Agent check meant to keep browsers out is spoofable in Firefox and Safari. DNS rebinding does the rest.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • CVE-2025-62593 is a critical remote code execution vulnerability in Ray, exploitable via the Firefox and Safari browsers through a DNS rebinding attack.
  • Developers working with Ray as a development tool can be exploited via this critical RCE vulnerability.
  • The Ray development team has a longstanding decision not to implement any authentication on critical endpoints, including /api/jobs and /api/job_agent/jobs/.
  • The current defense against browser-based attacks checks whether the request's User-Agent header starts with the string 'Mozilla' and rejects it if so.
  • The is_browser_request code comment describes the heuristic as 'very weak' and assumes that fetch and XHR cannot alter the User-Agent header.

Compiled by The WatchSomething wrong?How this is made

Why it matters

The Ray project's long-standing decision not to authenticate its job-submission endpoints is now reachable from an ordinary web browser [3]. CVE-2025-62593 means an ML engineer running a local Ray node can be handed remote code execution by visiting a malicious page or being served a malvertisement [1][10].

The exposed endpoints are `/api/jobs` and `/api/job_agent/jobs/`, which carry no authentication [3]. The only barrier against browser-driven abuse is a check that rejects any request whose `User-Agent` header starts with the string "Mozilla" [4]. The code's own comment concedes the heuristic is "very weak," resting on the assumption that `fetch` and XHR cannot alter the User-Agent header [5].

That assumption is wrong for two of the three major browsers. The fetch specification permits the User-Agent header to be set to a different value, and both Firefox and Safari honor it [6]. Chrome is not vulnerable, according to the advisory, only because of a bug that puts it out of spec with fetch [7]. The defense is not authentication; it is a string prefix an attacker controls.

The remaining obstacle is reaching a service bound to the developer's own machine. DNS rebinding solves that, and the advisory notes it is trivially performed with tooling such as nccgroup's Singularity [8]. Chained together, an attacker spoofs the User-Agent, rebinds DNS to the local Ray dashboard on TCP port 8265, and invokes the jobs API to execute code [8][9]. The published proof of concept pops a calculator, but the report states the payload can be modified for other operating systems and implementations [11].

This is not a lab-only concern. The researcher reports getting the attack to work repeatedly on macOS across multiple residential networks around Seattle [12]. Some corporate networks may block DNS rebinding, though the advisory expects not many will [13]. The failure mode is the developer laptop that runs `ray start --head` and then opens a browser tab, which is the normal workflow.

The advisory is blunt that this refusal to authenticate has "once again" produced a severe vulnerability, framing it as a recurring consequence of a design choice rather than a one-off bug [14]. A User-Agent prefix is a filter, not a credential, and any control that an attacker's own client can set will eventually be set.

What to watch: the full proof of concept was scheduled to go live at the time of disclosure [15]. Operators running Ray in development should treat the dashboard port as internet-adjacent even when it is bound to localhost, and should not assume the "Mozilla" guard protects Firefox or Safari users. The durable fix is authentication on the job endpoints; until Ray ships that, the mitigation is network isolation of port 8265 and not browsing while a head node is up.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories