← Back to Feed

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

CVE-2026-59726

July 29, 2026 · The Hacker News · Severity: HIGH

A maximum-severity vulnerability (CVE-2026-59726, CVSS 10.0) was discovered in Ruflo, an open-source agent meta-harness for Claude Code and Codex. The flaw, named RufRoot, exposes 233 tools including shell command execution, database operations, agent management, and memory storage through an unauthenticated MCP bridge bound to 0.0.0.0 by default. This allows unauthenticated remote attackers to execute arbitrary commands, poison AI agent memory, access stored credentials, and manipulate AI-driven workflows. The vulnerability affects all versions before 3.16.3.

Key Takeaways

  • CVE-2026-59726 (CVSS 10.0) in Ruflo exposes 233 unauthenticated tools including shell execution and memory storage over the network by default, enabling full remote code execution.
  • Attackers can poison AI agent memory, steal credentials from the MCP knowledge graph, and manipulate autonomous workflows due to the open bridge.
  • Users must update to Ruflo version 3.16.3+ and ensure the MCP bridge is not exposed to untrusted networks.
☕ Buy a Coffee