CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Covered by 2 sources
Read full postThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical remote code execution vulnerability in the Ray distributed computing framework to its Known Exploited Vulnerabilities list. The flaw, exploitable via DNS rebinding attacks in browsers like Firefox and Safari, affects developers running Ray in development environments and has been fixed in Ray version 2.52.0.




