Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-59726: Ruflo: Unauthenticated attackers can access sensitive data

CVE-2026-59726 CVE-2026-59726
Summary

An older version of Ruflo's default setup allowed anyone on the network to access sensitive data without a password. This could let them read important keys and interfere with Ruflo's learning patterns. The issue is fixed in version 3.16.3, so update to that version to stay safe.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
ruvnet ruflo < 3.16.3
Original title
Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authenti...
Original description
Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns. This issue is fixed in version 3.16.3.
nvd CVSS3.1 10.0
Vulnerability type
CWE-78 OS Command Injection
CWE-306 Missing Authentication for Critical Function
CWE-942
Published: 9 Jul 2026 · Updated: 20 Jul 2026 · First seen: 9 Jul 2026