Skip to content
The Nexus
SECURITYJul 29 · 15:39 UTCTHE HACKER NEWS[email protected] (The Hacker News)

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Cybersecurity researchers identified a critical security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allowing unauthenticated remote code execution. The vulnerability, CVE-2026-59726 (CVSS score: 10.0), affects versions before 3.16.3 and was codenamed RufRoot by Noma Security.

Nexus surfaces and summarizes. The full story lives at the source.

Mentioned
Spot something wrong with this article?Report a problem →
Forward this
Related Signal

Adjacent reporting