CVE-2026-59726
CVSS 10 CRITICAL: ruflo is an agent meta-harness for Claude Code and Codex. EPSS 7% (94th percentile), up from 0.5%.
Vulnerabilities · 46 days ago
The break is in the trust boundary, not just the code bug. A default Ruflo deployment leaves its MCP bridge reachable without login, so one network request can act like an authorized operator and take control of the agent control plane. That is bad enough on its own; the harder problem is that the platform’s own memory can be altered so the bad behavior survives patching.
Noma Labs tracked the flaw as CVE-2026-59726, or RufRoot. It affects Ruflo before 3.16.3 and can expose provider API keys, stored conversations, and AgentDB learning data through the unauthenticated bridge on port 3001 in the default docker-compose setup.
For operators of Ruflo and similar AI orchestration platforms, the risk does not end when the version is fixed. If the attacker reached memory or secrets before remediation, the platform can stay operationally unsafe after the patch lands.
CVSS 10 CRITICAL: ruflo is an agent meta-harness for Claude Code and Codex. EPSS 7% (94th percentile), up from 0.5%.
3 sources covering this story
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container.
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Ruflo CVE-2026-59726 exposes an unauthenticated MCP bridge that could enable RCE, LLM key theft, conversation access, and AI memory poisoning.
Patch-Resistant Ruflo Flaw Can Unleash Malicious AI Agent Swarms
The flaw in the AI hosting platform Ruflo allows an unauthenticated attacker to take over and corrupt memory, so bad behavior persists after patching.
Part of the PlainSec briefing for 2026-07-29