SECURITYTHE HACKER NEWS
Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
Cybersecurity researchers identified a critical security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allowing unauthenticated remote code execution. The vulnerability, CVE-2026-59726 (CVSS score: 10.0), affects versions before 3.16.3 and was codenamed RufRoot by Noma Security.
Mentioned
Related Signal
Adjacent reporting
- Anthropic MCP Design Vulnerability Enables RCE, Threatening AI Supply Chain
- Critical Unpatched Flaw Leaves Hugging Face LeRobot Open to Unauthenticated RCE
- GitHub RCE Vulnerability: CVE-2026-3854 Breakdown
- Autonomous AI Tool Finds 2-Year-Old RCE Flaw in Redis (CVE-2026-23479)
- Anthropic response to 1-click pwn: Shouldn't have clicked 'ok'