Security · 1h ago
Critical Ruflo Bug Lets Hackers Execute Code Remotely
A maximum-severity vulnerability (CVE-2026-59726, CVSS 10.0) in Ruflo, an open-source agent harness for Claude Code and Codex, allows unauthenticated remote code execution. The flaw, dubbed RufRoot, affects all versions before 3.16.3. Researchers urge immediate patching to prevent AI memory poisoning and command injection.
Meridian48 take
The CVSS 10.0 rating underscores how dangerous unauthenticated RCE in AI tooling can be, especially as agentic frameworks gain adoption.
Read the full reporting
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory →
The Hacker News
rufloremote-code-execution