The vulnerability (CVE-2025-62593) in Ray is a Remote Code Execution (RCE) exploitable via Safari and Firefox browsers through a DNS Rebinding Attack. The core issue is an insufficient guard against browser-based attacks, where the system relied on checking if the User-Agent header started with 'Mozilla'. This defense is flawed because the User-Agent header can be easily modified or spoofed.
Upon analyzing the provided commit 70e7c72780bdec075dba6cad1afe0832772bfe09, two key files were modified:
-
python/ray/dashboard/http_server_head.py: The browsers_no_post_put_middleware function was modified. Previously, it only used dashboard_optional_utils.is_browser_request(request) to identify browser traffic for blocking POST/PUT requests. The patch adds an OR condition to also check dashboard_optional_utils.has_sec_fetch_headers(request). This indicates that the original browsers_no_post_put_middleware function was vulnerable because its browser detection mechanism was easily bypassed.
-
python/ray/dashboard/optional_utils.py: This file introduces a new function has_sec_fetch_headers (which is a mitigation, not a vulnerable function itself) and modifies the deny_browser_requests function. Specifically, the decorator function nested within deny_browser_requests was updated. Before the patch, it only checked is_browser_request(req). The patch adds an if has_sec_fetch_headers(req): check before the is_browser_request check. This demonstrates that the decorator function within deny_browser_requests was also vulnerable due to its reliance on the easily spoofed User-Agent header for browser detection.
Therefore, the functions browsers_no_post_put_middleware and deny_browser_requests.<locals>.decorator are identified as vulnerable because they contained the insufficient browser detection logic that allowed the vulnerability to be exploited. These functions would appear in a runtime profile when an attacker successfully bypasses the intended browser protection to perform unauthorized actions, leading to RCE.