NPM · AUGUST 2026 · EARLY WARNING

Ray-Project Ray npm Package: Code Injection Vulnerability Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
HIGH
Affected component
ray-project ray (npm)
Affected versions
>= ray-0.7.0, <= ray-0.7.0 or >= ray-0.6.5, <= ray-0.6.5 or >= ray-0.6.4, <= ray-0.6.4 or >= ray-0.6.3, <= ray-0.6.3 or >= ray-0.6.2, <= ray-0.6.2 or >= ray-0.6.1, <= ray-0.6.1 or >= ray-0.6.0, <= ray-0.6.0 or >= ray-0.5.3, <= ray-0.5.3 or >= ray-0.5.2, <= ray-0.5.2 or >= ray-0.5.1, <= ray-0.5.1 or >= ray-0.5.0, <= ray-0.5.0 or >= ray-0.4.0, <= ray-0.4.0 or >= ray-0.3.1, <= ray-0.3.1 or >= ray-0.3.0, <= ray-0.3.0 or >= ray-0.2.2, <= ray-0.2.2 or >= ray-0.2.1, <= ray-0.2.1 or >= ray-0.2.0, <= ray-0.2.0 or >= ray-0.1.2, <= ray-0.1.2 or >= ray-0.1.1, <= ray-0.1.1 or >= ray-0.1.0, <= ray-0.1.0
Patched version
Not yet available
CVE-2025-62593

An early warning has been issued for a code injection vulnerability in the Ray-Project Ray npm package. Developers using Ray may be at risk.

What happened

The Ray-Project Ray npm package reportedly contains a code injection vulnerability that could allow remote code execution. This vulnerability is exploitable through Firefox and Safari. The package versions affected range from ray-0.1.0 to ray-0.7.0 inclusive. The exploit is under investigation and has been flagged as being used in the wild.

Developers who have incorporated Ray into their development workflow should assess their exposure to this vulnerability. The exploit mechanism involves the injection of malicious code which could be executed remotely under certain conditions.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If ray-project ray is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Ray-Project Ray npm package versions from ray-0.1.0 to ray-0.7.0 inclusive, you may be affected.

What should I do right now?

Upgrade to the latest version of Ray-Project Ray and monitor your environments for suspicious activity.

Has this been exploited in the wild?

Yes, this vulnerability appears to have been exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats