PT-2026-56898 · Ruflo · Ruflo
CVE-2026-59726
·
Published
2026-07-09
·
Updated
2026-09-03
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ruflo versions prior to 3.16.3
Description
Ruflo, an agent meta-harness for Claude Code and Codex, contains a flaw in its default docker-compose deployment where the MCP bridge endpoints 'POST /mcp' and 'POST /mcp/:group' are exposed without authentication. An unauthenticated network attacker can exploit this by invoking the
terminal execute tool via tools/call to obtain a shell within the bridge container. This access allows the attacker to steal provider API keys and poison AgentDB learning-store patterns, which are data structures that persist between sessions to influence agent behavior. According to Trend Micro, the number of unauthenticated MCP servers on the internet increased from 492 to 1,467.Recommendations
Update to version 3.16.3.
Restrict the MCP bridge to localhost.
Implement mandatory authentication for the MCP bridge.
Apply the principle of least privilege to tools and use an allow-list.
Require human confirmation for irreversible actions.
Exploit
Fix
RCE
Missing Authentication
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ruflo