Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Summary
A critical vulnerability in the open-source agent meta-harness Ruflo allows unauthenticated attackers to execute remote code and poison AI memory. Tracked as CVE-2026-59726, the flaw impacts all versions prior to 3.16.3 and has been dubbed RufRoot by Noma Security.
IFF Assessment
FOE
This vulnerability enables unauthenticated remote code execution, posing a significant risk to systems and data.
Severity
10.0
Critical
Defender Context
Defenders should prioritize patching or updating Ruflo instances to version 3.16.3 or later to mitigate the risk of remote code execution and AI memory poisoning. This vulnerability highlights the growing security concerns around open-source AI tools and the importance of thorough security vetting for such projects.