The record
Written from the 1 report below. Nothing here is unsourced.
- Security researchers have found a maximum-severity flaw, CVE-2026-59726 (CVSS 10.0, codenamed RufRoot), in the open-source Ruflo AI orchestration platform, which affects all versions before 3.16.3.
- The flaw let unauthenticated attackers send a single HTTP request to an exposed port and gain full remote code execution, steal LLM API keys, read user conversations, and poison the AI's memory to influence future responses.
- The maintainer pushed a fix within 24 hours of responsible disclosure, and the patch makes the bridge bind to localhost and adds authentication controls.
- Operators of exposed instances are advised to close ports 3001 and 27017, rotate API keys, audit the AgentDB memory store, and rebuild containers from clean images.
What to watch next
- Check whether any Ruflo deployments you rely on were exposed and have been upgraded to version 3.16.3 or later.
- Look for follow-up reports on whether attackers exploited this flaw in the wild or stole API keys.
- Track whether similar unauthenticated MCP bridge issues surface in other AI orchestration tools.
Coverage1
1 report
English national1
All filed from India
Named United States · Anthropic Claude Code · GitHub · Mongodb · OpenAI Codex · Ruflo · Eli Ainhorn · National Vulnerability Database · NIST · Noma Labs · Noma Security · Reuven Cohen
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
