Skip to content
archivevulnerability · 29 Jul 2026 · 15:39 UTC

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

VULNCVE-2026-59726source · THN

last 60 dispatches · spectrum

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. …

CVE · detail
grounded ✓primary source ↗
Early access

Get the next one first.

Early access opens the actor API and MCP server first, plus alerts when an adversary you follow lands on the wire. One email when it's ready. Nothing else, ever.

bot-protected