CPE
high
threat
Active Exploitation of Code Injection Vulnerability in Ray
2 TTPs 1 CVECISA has added CVE-2025-62593, a code injection vulnerability in the Ray framework, to its Known Exploited Vulnerabilities catalog following reports of active exploitation.
exploited
Ray
2t
1c
updated
high
advisory
CVE-2026-57516: Ray Unsafe Deserialization Leading to RCE
1 TTP 1 CVEAn unsafe deserialization vulnerability (CVE-2026-57516) exists in the WebDataset reader of the Ray framework prior to version 2.56.0, allowing remote attackers to achieve arbitrary code execution on Ray remote workers by supplying a malicious tar archive to the `read_webdataset()` function, which then unconditionally calls `pickle.loads()` on .pkl/.pickle entries or `torch.load()` with `weights_only=False` on .pt/.pth entries, executing arbitrary code.
Ray
vulnerability
deserialization
rce
execution
1t
1c
updated