← Back to blog

CISA Warns of Actively Exploited Ray Framework RCE Flaw

A critical vulnerability in the Ray distributed computing framework is under active attack. Organizations using Ray for AI/ML workloads should prioritize patching.

TL;DR

  • CISA adds Ray framework vulnerability to KEV catalog due to active exploitation
  • The flaw enables browser-based remote code execution (RCE)
  • Ray is widely used for scaling AI and machine learning applications
  • Organizations must update affected systems immediately
  • The vulnerability underscores risks in open-source ML infrastructure

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical vulnerability in the Ray distributed computing framework to its Known Exploited Vulnerabilities catalog. The flaw, which can lead to remote code execution through browser-based attacks, is already being exploited in the wild.

Ray is an open-source framework built for Python that helps developers scale artificial intelligence and machine learning workloads across clusters. With thousands of projects relying on Ray for high-performance computing, this vulnerability poses a significant risk to organizations in the AI and data science sectors.

Vulnerability Details

  • The specific vulnerability allows for browser-based remote code execution when processing untrusted inputs
  • It affects certain versions of Ray commonly deployed in enterprise AI environments
  • Attackers can exploit the flaw without requiring prior authentication
  • Exploitation could lead to full system compromise and lateral movement within networks

Impact and Recommendations

  • Organizations using Ray should audit their deployments immediately
  • Affected instances should be updated to patched versions released by the Ray team
  • Security teams should monitor network traffic for signs of exploitation attempts
  • Consider implementing additional input sanitization and access controls as temporary mitigations
  • Review dependencies and integrations that rely on Ray to assess broader exposure

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.