Critical zero-auth flaw in Ruflo AI platform exposes sensitive data
A CVSS 10.0 vulnerability dubbed RufRoot was discovered in Ruflo, an AI platform bridge tool, allowing unauthenticated attackers to execute commands and access AI provider API keys, stored conversations, and persistent agent memory. The flaw was a complete authentication bypass.