Prnewswire
Critical Vulnerability in Ruflo AI Platform Allows Full Control via Single Request
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Noma Labs has disclosed a critical vulnerability, CVE-2026-59726, in the open-source AI platform Ruflo, allowing unauthenticated attackers to achieve full remote code execution with a single HTTP request. This vulnerability, dubbed 'RufRoot', has a maximum CVSS score of 10.0 and exposes hundreds of AI tools, enabling attackers to steal API keys, access user conversations, and tamper with AI memory. The flaw was discovered on June 30, 2026, and reported to Ruflo maintainers, who quickly released a fix within 24 hours, locking down the platform by default. Organizations using Ruflo are advised to rotate credentials and audit AI memory for tampering. The vulnerability affects a widely adopted platform with approximately 66,000 GitHub stars, making it a significant risk for users in the Model Context Protocol ecosystem.
Key Points: • CVE-2026-59726 allows full remote code execution on Ruflo with a single unauthenticated request. • The vulnerability was disclosed on June 30, 2026, and has a maximum CVSS score of 10.0. • Organizations must audit AI memory and rotate credentials due to the potential for long-term tampering.