SCA: security update for ray (GHSA-q279-jhrf-cc6v)

critical Tenable Cloud Security Plugin ID 437184

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool
can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability
is due to an insufficient guard against browser-based attacks, as the current defense uses the User-Agent
header starting with the string "Mozilla" as a defense mechanism. This defense is insufficient as the
fetch specification allows the User-Agent header to be modified. Combined with a DNS rebinding attack
against the browser, and this vulnerability is exploitable against a developer running Ray who
inadvertently visits a malicious website, or is served a malicious advertisement (malvertising). This
issue has been patched in version 2.52.0. (CVE-2025-62593)

See Also

https://github.com/advisories/GHSA-q279-jhrf-cc6v

Plugin Details

Severity: Critical

ID: 437184

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 1/28/2026

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: High

Score: 7.1

Percentile: 98.45

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2025-62593

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS v4

Risk Factor: Critical

Base Score: 9.4

Threat Score: 8.6

Threat Vector: CVSS:4.0/E:P

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 11/26/2025

Vulnerability Publication Date: 11/26/2025

Reference Information

CVE: CVE-2025-62593