BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

RufRoot vulnerability allows unauthenticated RCE in Ruflo

Critical Ruflo AI agent flaw enables unauthenticated remote code execution via exposed MCP bridge.

  • A maximum-severity vulnerability (CVE-2026-59726, CVSS 10.0) in the open-source AI agent platform Ruflo allows unauthenticated remote code execution.
  • The flaw, codenamed RufRoot, exploits an unauthenticated Model Context Protocol bridge exposed on port 3001 by default in docker-compose deployments.
  • Attackers can gain shell access, steal LLM API keys, poison AI memory, and deploy persistent backdoors.
  • The maintainer released a fix in version 3.16.3 within 24 hours of disclosure, binding the bridge to loopback and enabling authentication.
  • Operators must close exposed ports, rotate all API keys, audit the AgentDB for tampering, and rebuild containers from clean images.

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source AI agent meta-harness, that could lead to unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score 10.0), impacts all versions before 3.16.3 and has been codenamed RufRoot by Noma Security’s research team.

- Advertisement -

The crux of the issue is that Ruflo exposed 233 tools through an unauthenticated Model Context Protocol bridge open to the network by default. Specifically, the docker-compose.yml configuration binds port 3001 to 0.0.0.0, making any network-reachable instance fully exploitable without authentication.

Consequently, a single unauthenticated HTTP POST to port 3001 can invoke the terminal_execute tool and obtain a shell inside the bridge container. Armed with this foothold, an attacker could siphon API keys used to interact with LLM providers, read every user conversation, and interfere with the AI system’s memory to influence model responses.

Following responsible disclosure on June 30, 2026, the project’s maintainer, Reuven Cohen, pushed a fix within 24 hours. The patch now binds the MCP bridge to the loopback interface, gates terminal_execute behind server-side controls, and enables MongoDB authentication.

Operators running exposed instances are recommended to immediately close firewall ports 3001 and 27017, rotate all LLM API keys, and audit the AgentDB pattern store for injected entries. Noma warned that the ability to write malicious instructions into persistent AI memory means an attacker can influence responses to every future user, long after the original intrusion ends.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Coldcard adds user entropy to seed generation after $112M exploit

Coinkite released firmware 5.6.1 for Coldcard Mk4/Mk5 and 1.5.1Q for Coldcard Q, requiring user-supplied...

GitLab Flaw Actively Exploited After Disclosure

A critical GitLab vulnerability (CVE-2026-19478, CVSS 9.4) enables unauthenticated attackers to modify or delete...

PEPE Surges 25% Weekly, Outperforms Bitcoin and Ethereum

PEPE surged 14.2% in 24 hours and over 25% in the past week, outperforming...

Tom Lee: Avoid Robinhood Stock in 2026

Tom Lee of Fundstrat named Robinhood Markets Inc stock as one to avoid in...

MANTRA Token Plunges 18.5% as Chain Halts After Incident

MANTRA's native token plunged 18.5% to an all-time low of $0.004126 before the chain...

Must Read

How To Travel With Bitcoin: 9 Travel Companies Accepting Bitcoin

Bitcoin travel is a reality, as several travel companies now accept payments in cryptocurrencies for their services.Those who have opened a Bitcoin account on...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading