Critical Vulnerability in Ruflo AI Platform Allows Full Control via Single Request

Critical Vulnerability in Ruflo AI Platform Allows Full Control via Single Request

First seen 29 Jul 2026, 17:15 UTC PrnewswireGbhackersDarkreading 75% similarity 78.0

Article Content

Browse articles
ThreatCluster

Noma Labs has disclosed a critical vulnerability, CVE-2026-59726, in the open-source AI platform Ruflo, allowing unauthenticated attackers to achieve full remote code execution with a single HTTP request. This vulnerability, dubbed 'RufRoot', has a maximum CVSS score of 10.0 and exposes hundreds of AI tools, enabling attackers to steal API keys, access user conversations, and tamper with AI memory. The flaw was discovered on June 30, 2026, and reported to Ruflo maintainers, who quickly released a fix within 24 hours, locking down the platform by default. Organizations using Ruflo are advised to rotate credentials and audit AI memory for tampering. The vulnerability affects a widely adopted platform with approximately 66,000 GitHub stars, making it a significant risk for users in the Model Context Protocol ecosystem.

Key Points: • CVE-2026-59726 allows full remote code execution on Ruflo with a single unauthenticated request. • The vulnerability was disclosed on June 30, 2026, and has a maximum CVSS score of 10.0. • Organizations must audit AI memory and rotate credentials due to the potential for long-term tampering.

ThreatCluster AI How this analysis works

Timeline

2026-06-30
Vulnerability discovered and reported
Noma Labs found a critical flaw in Ruflo, exposing it to full remote code execution and reported it to maintainers.
Prnewswire
2026-07-09
CVE-2026-59726 published
The vulnerability was officially published, detailing its severity and exploitation method.
Gbhackers
2026-07-29
Ruflo patch released
Ruflo maintainers released a fix that defaults the platform to a locked-down configuration requiring authentication.
Prnewswire

Community

Browse all →

Tracked Entities in This Story