CVE Tools
Back to feed
Exploitation report Ruflo ai-ml rce

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

Researchers have identified a critical vulnerability in Ruflo, an open-source AI orchestration platform, that allowed unauthenticated attackers to execute arbitrary commands and manipulate AI memory. Tracked as CVE-2026-59726 (CVSS score: 10.0), the flaw impacted all versions prior to 3.16.3 due to an insecurely configured Model Context Protocol (MCP) bridge. This enabled remote exploitation without authentication, leading to potential API key theft, AI memory poisoning, and persistent backdoors. A fix was quickly deployed by the project’s maintainer, Reuven Cohen, who updated the default configuration to restrict access and add security controls.