Critical remote-code execution flaw found in Ruflo AI framework
Noma Labs disclosed CVE-2026-59726, a maximum-severity vulnerability (CVSS 10.0) in Ruflo, an open-source AI orchestration harness used with Claude Code and OpenAI Codex. Unauthenticated attackers can execute arbitrary commands and poison AI agent memory.