< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-29T21:09:30+05:30

Critical Remote Code Execution Vulnerability in Ruflo MCP Enables AI Memory Poisoning

A critical remote code execution vulnerability (CVE-2026-59726) in Ruflo MCP allows unauthenticated attackers to execute arbitrary commands and poison AI memory, with a CVSS score of 10.0. The flaw was swiftly patched after disclosure, but affected systems face risks including LLM API key theft and persistent AI memory tampering.

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.

The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

Read original article

*** END OF TRANSMISSION ***