Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Source: The Hacker News

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.

The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all ve


Read original