Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Summary

A critical vulnerability in the open-source agent meta-harness Ruflo allows unauthenticated attackers to execute remote code and poison AI memory. Tracked as CVE-2026-59726, the flaw impacts all versions prior to 3.16.3 and has been dubbed RufRoot by Noma Security.

IFF Assessment

FOE

This vulnerability enables unauthenticated remote code execution, posing a significant risk to systems and data.

Severity

10.0 Critical

The vulnerability allows for unauthenticated remote code execution, indicating a critical severity due to its high attack vector and complete loss of integrity and availability.

Defender Context

Defenders should prioritize patching or updating Ruflo instances to version 3.16.3 or later to mitigate the risk of remote code execution and AI memory poisoning. This vulnerability highlights the growing security concerns around open-source AI tools and the importance of thorough security vetting for such projects.

Read Full Story →