The break is in the trust boundary, not just the code bug. A default Ruflo deployment leaves its MCP bridge reachable without login, so one network request can act like an authorized operator and take control of the agent control plane. That is bad enough on its own; the harder problem is that the platform’s own memory can be altered so the bad behavior survives patching.
Noma Labs tracked the flaw as CVE-2026-59726, or RufRoot. It affects Ruflo before 3.16.3 and can expose provider API keys, stored conversations, and AgentDB learning data through the unauthenticated bridge on port 3001 in the default docker-compose setup.
For operators of Ruflo and similar AI orchestration platforms, the risk does not end when the version is fixed. If the attacker reached memory or secrets before remediation, the platform can stay operationally unsafe after the patch lands.