CVE-2026-59726
CVSS 10 CRITICAL: ruflo is an agent meta-harness for Claude Code and Codex. EPSS 3% (87º percentile).
Vulnerabilità ed exploit
Il problema non è solo l’RCE senza login nel deployment predefinito. In Ruflo, chi entra nel bridge MCP può anche alterare la memoria dell’agente e lasciare istruzioni malevole che continuano a influenzare il comportamento dopo la patch; il classico aggiornare e ripartire non chiude tutto il perimetro.
Le fonti indicano che il default docker-compose esponeva il bridge MCP su rete, con gli endpoint /mcp aperti senza autenticazione. Da lì era possibile ottenere shell, leggere le API key dei provider, vedere le conversazioni salvate e avvelenare l’AgentDB; la correzione è in Ruflo 3.16.3.
Per chi usa piattaforme di agent orchestration con tool bridge raggiungibili in rete, il punto non è solo correggere il bug. Se sono passate credenziali o memoria di apprendimento, vanno considerati compromessi anche dopo l’aggiornamento.
3 fonti · 30 lug
CVSS 10 CRITICAL: ruflo is an agent meta-harness for Claude Code and Codex. EPSS 3% (87º percentile).
SecurityWeek
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container.
originaleThe Hacker News
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Ruflo CVE-2026-59726 exposes an unauthenticated MCP bridge that could enable RCE, LLM key theft, conversation access, and AI memory poisoning.
originaleDark Reading
Patch-Resistant Ruflo Flaw Can Unleash Malicious AI Agent Swarms
The flaw in the AI hosting platform Ruflo allows an unauthenticated attacker to take over and corrupt memory, so bad behavior persists after patching.
originalePart of the PlainSec briefing for 2026-07-29
Every edition of this story: Il patch non basta: Ruflo può restare corrotto dopo la correzione