Security· August 18, 2026 at 03:26 p.m.
Urgent Action Required: Critical Remote Code Execution Bug in Ray Framework Affects Major Tech Companies
Key takeaways
- The vulnerability is rated 9.4 under CVSS v4
- It affects major tech companies including Amazon, Apple, and OpenAI
- The bug allows an attacker to execute arbitrary shell code on a developer's machine
A critical Remote Code Execution (RCE) vulnerability, tracked as CVE-2025-62593 and rated 9.4 under CVSS v4, has been identified in the widely used open source framework Ray. The bug allows attackers to exploit vulnerable Ray systems using Firefox or Safari for RCE. This vulnerability primarily impacts developers running development/testing environments with Ray.