Critical Ruflo flaw CVE-2026-59726 lets attackers hijack AI agents via unauthenticated MCP Bridge
A critical vulnerability, CVE-2026-59726, dubbed RufRoot, has been discovered in Ruflo's MCP Bridge, disclosed by Noma Labs and reported by SecurityWeek on July 30, 2026. The flaw allows any attacker to send a single unauthenticated POST request to TCP port 3001, which is exposed on all interfaces by default, to execute arbitrary commands inside the Docker container. Exploiting the vulnerability enables theft of LLM provider API keys from OpenAI, Anthropic, Google, and OpenRouter, as well as hijacking of AI agent swarms and poisoning of long-term agent memory stored in MongoDB. Attackers can also achieve persistent access by injecting malicious code into the application and surviving Docker restarts, with no user interaction required. Ruflo users are advised to update to the patched version immediately and restrict MCP Bridge access to localhost or a secured management network with proper authentication.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in