[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fg3S0XpQNgkMhoTJlmmcnPLeGJeCTWVr275Q4g65mFZY":3},{"article":4,"iocs":51},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":28,"category":29,"article_tags":33},"81bf2685-0b4e-42fb-a371-4a9cdc8caf53","CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In","cvss-10-0-rufroot-flaw-allowed-attackers-to-hijack-ruflo-without-logging-in-732d70","Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.","A critical CVSS 10.0 vulnerability, dubbed RufRoot (CVE-2026-59726), has been discovered in the open-source AI agent coordination platform Ruflo. The flaw allowed unauthenticated attackers to execute commands within the MCP bridge container, potentially stealing AI provider keys, accessing stored chats, and altering persistent agent memory. While Ruflo has released version 3.16.3 to fix the default configuration, organizations must verify the integrity of their AgentDB even after patching.","CVSS 10.0 RufRoot flaw allowed attackers to hijack Ruflo without logging in.","SecurityCVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk. byWaqasJuly 29, 20263 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening A vulnerable Ruflo deployment could be reached without authentication, and a single network request was enough to execute commands inside the MCP bridge container, according to research published by Noma Security. The flaw, named RufRoot and tracked as CVE-2026-59726, received the maximum CVSS score of 10.0. It affects Ruflo versions before 3.16.3 when deployed using the project’s previous default Docker Compose configuration. Ruflo, formerly known as Claude Flow, is an open-source platform that coordinates AI agents, gives them access to tools, and maintains information between sessions. It works as a supporting layer for coding agents such as Claude Code and Codex. The vulnerability is in Ruflo, not in Claude Code or Codex themselves. No Login Required to Access Agent Tools The previous default configuration exposed Ruflo’s Model Context Protocol (MCP) bridge to the network without authentication. MCP allows AI systems to call external tools, including tools that interact with files, databases, and operating-system commands. Noma Labs found that an attacker could send a request to the exposed bridge and invoke Ruflo’s terminal_execute tool. This provided command execution inside the bridge container and access to the 233 tools exposed through the MCP bridge. From there, the attacker could read API keys used to connect with AI providers and access conversations stored by the affected deployment. Stolen provider keys could also be used outside Ruflo, leaving the account owner responsible for unauthorized AI usage and related charges. The same access allowed researchers to modify AgentDB, Ruflo’s persistent learning and memory store. Malicious instructions placed there could later be retrieved by agents and influence how they respond to tasks from other users. Patching Does Not Remove Poisoned Memory According to researchers, memory tampering changes the recovery process because updating Ruflo closes the original entry point but does not remove instructions already written into AgentDB. An organization could therefore be running patched software while its agents continue using altered information from an earlier compromise. Ram Varadarajan, CEO of cyber deception company Acalvio, said software updates stop further access but do not reverse changes already made to persistent agent memory. He argued that organizations must verify the integrity of an AI system’s stored knowledge before trusting its behaviour after an incident. This does not mean every vulnerable deployment was compromised. No evidence of active exploitation has been reported. However, administrators who exposed the affected MCP bridge should not treat an upgrade alone as proof that their installation is clean. Ruflo Fixed the Default Configuration Noma Labs disclosed the vulnerability to Ruflo’s maintainers on June 30, 2026, along with a working proof of concept tested against a live default deployment. The maintainers released a fix within 24 hours, and Noma independently confirmed that it blocked the reported attack. Ruflo version 3.16.3 changed the default deployment to a locked configuration. Public access now requires explicit configuration and authentication. The official CVE record also confirms that versions before 3.16.3 are affected. Anyone running an older version should update immediately, check whether the MCP bridge was reachable from outside trusted networks, and review logs for unexpected tool calls or shell commands. Noma also recommends rotating AI provider keys, rebuilding affected containers from clean images, and examining AgentDB for unfamiliar instructions or altered learning patterns. The full RufRoot report provides technical details and remediation guidance. Waqas I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism. View Posts Claude FlowCybersecurityNoma SecurityRufloRufRootVulnerability Leave a Reply Cancel reply View Comments (0) Related Posts Read More Android Malware Security New HyperRat Android Malware Sold as Ready-Made Spy Tool Researchers have uncovered HyperRat, a new Android malware sold as a service, giving attackers remote control, data theft tools, and mass phishing features. byWaqas Read More Security Malware New malware mimics Windows scanner to infect PCs with ransomware This trojan horse was discovered which pretends to be a Windows scanner by Microsoft but in reality, it is everything evil but so. bySudais Asif Read More Security Cyber Crime Ukraine Busts Pro-Russia Hackers Who Stole 30M Accounts of EU Citizens According to the Ukraine Security Service (SSU), the hackers were selling the hacked accounts to “Russian propagandists” through the dark web. byWaqas Read More Security Malware Phishing Scam Fake Ukraine Police Notices Spread New Amatera Stealer and PureMiner FortiGuard Labs exposes a high-severity phishing campaign impersonating the National Police of Ukraine to deliver Amatera Stealer (data theft) and PureMiner (cryptojacking) to Windows PCs. byDeeba Ahmed","https:\u002F\u002Fhackread.com\u002Frufroot-vulnerability-attackers-hijack-ruflo-login\u002F","https:\u002F\u002Fhackread.com\u002Fwp-content\u002Fuploads\u002F2026\u002F07\u002FRufRoot-Attack-Flow.mp4","2026-07-29T14:58:15+00:00","2026-07-29T16:00:21.712864+00:00",9,[18,21,24,26],{"name":19,"type":20},"Ruflo","product",{"name":22,"type":23},"AI agents","technology",{"name":25,"type":20},"Claude Code",{"name":27,"type":20},"Codex","80544778-fabb-4dcd-aa35-17492e5dcf4f",{"id":28,"icon":30,"name":31,"slug":32},null,"Vulnerabilities","vulnerabilities",[34,36,41,46],{"category":35},{"id":28,"icon":30,"name":31,"slug":32},{"category":37},{"id":38,"icon":30,"name":39,"slug":40},"839da5c1-3c34-47e2-9499-f7201640e3ac","AI Security","ai-security",{"category":42},{"id":43,"icon":30,"name":44,"slug":45},"ade75414-7914-4e23-a450-48b64546ee70","Open Source","open-source",{"category":47},{"id":48,"icon":30,"name":49,"slug":50},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[52],{"type":53,"value":54,"context":55},"cve","CVE-2026-59726","RufRoot vulnerability in Ruflo"]