PT-2026-56898 · Ruflo · Ruflo

CVE-2026-59726

·

Published

2026-07-09

·

Updated

2026-09-03

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ruflo versions prior to 3.16.3
Description Ruflo, an agent meta-harness for Claude Code and Codex, contains a flaw in its default docker-compose deployment where the MCP bridge endpoints 'POST /mcp' and 'POST /mcp/:group' are exposed without authentication. An unauthenticated network attacker can exploit this by invoking the terminal execute tool via tools/call to obtain a shell within the bridge container. This access allows the attacker to steal provider API keys and poison AgentDB learning-store patterns, which are data structures that persist between sessions to influence agent behavior. According to Trend Micro, the number of unauthenticated MCP servers on the internet increased from 492 to 1,467.
Recommendations Update to version 3.16.3. Restrict the MCP bridge to localhost. Implement mandatory authentication for the MCP bridge. Apply the principle of least privilege to tools and use an allow-list. Require human confirmation for irreversible actions.

Exploit

Fix

RCE

Missing Authentication

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59726
GHSA-C4HM-4H84-2CF3

Affected Products

Ruflo