CVE-2026-59726
Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
Description
Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns. This issue is fixed in version 3.16.3.
In plain language
AI Worth attentionIf you run Ruflo with the default Docker Compose setup before 3.16.3, attackers on the network can reach an open endpoint and run commands on your server container, steal stored API keys, and disrupt your Ruflo data—this is serious and you should act now.
In Ruflo versions prior to 3.16.3, the default Docker Compose deployment exposes the MCP bridge endpoints without authentication, enabling an unauthenticated remote attacker to trigger remote command execution in the bridge container, access stored API keys, and manipulate the internal AgentDB learning-store.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:CScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
- 3rd August – Threat Intelligence Reporten-us·Check Point Research· Incident Minnesota Water Systems data-breach
- Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarmsen-us·SecurityWeek· Exploitation Ruflo ai-ml
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memoryen·The Hacker News· Exploitation Ruflo ai-ml
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-59726 and every CVE in our database. Create a free account — no credit card required.
Create Free Account