Ruflo was found vulnerable to a maximum-severity flaw, CVE-2026-59726, that could let unauthenticated attackers achieve remote code execution through its exposed MCP bridge. The issue, dubbed RufRoot by Noma Labs, affected versions before 3.16.3 and could be used to steal LLM API keys, read user conversations, and poison AI memory. #Ruflo #CVE-2026-59726 #RufRoot #NomaLabs #ClaudeFlow
Keypoints
- Ruflo exposed 233 tools through an unauthenticated MCP bridge.
- The default docker-compose setup bound port 3001 to 0.0.0.0.
- A single HTTP POST could trigger remote code execution on vulnerable systems.
- Attackers could steal API keys, harvest conversations, and poison AgentDB memory.
- The fix in 3.16.3 added loopback binding, tool controls, and MongoDB authentication.
Read More: https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html