Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
The Hacker News
1 week ago

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

By info@thehackernews.com (The Hacker News)

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.