Exploitation report Ruflo ai-ml rce
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
CVE Tools coverage
Researchers at Noma Labs discovered a critical vulnerability in the open-source AI agent orchestration platform Ruflo, tracked as CVE-2026-59726 (CVSS score of 10/10). The flaw stems from an unauthenticated POST /mcp endpoint in the Model Context Protocol (MCP) bridge, allowing attackers to execute arbitrary commands within the container. This could lead to full system compromise, including stealing API keys, spawning rogue agent swarms, and manipulating AI outputs. The issue was fixed in version 3.16.3, with detailed remediation steps provided by the project maintainers.