Critical remote-code execution flaw found in Ruflo AI framework

Noma Labs disclosed CVE-2026-59726, a maximum-severity vulnerability (CVSS 10.0) in Ruflo, an open-source AI orchestration harness used with Claude Code and OpenAI Codex. Unauthenticated attackers can execute arbitrary commands and poison AI agent memory.

3 reportsother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

Researchers disclose critical Ruflo AI command-execution flaw

kite:cybersecurityother62d ago kagi ↗

Noma Labs disclosed a maximum-severity vulnerability in Ruflo, an open-source AI orchestration and agent meta-harness used with Anthropic Claude Code and OpenAI Codex [thehackernews.com#1][cybersecuritynews.com#1]. The flaw, tracked as CVE-2026-59726 with a CVSS score of 10.0 and codenamed RufRoot, affects all Ruflo versions before 3.16.3 [thehackernews.com#1][cybersecuritynews.com#1]. Researchers

🤖 CVE-2026-59726 (CVSS 10.0): Critical RCE in Ruflo, an open-source agent harness for Claude Code and OpenAI Codex. Unauthenticated attackers can execute arbitrary commands and poison AI agent memory

mastodon:infosec-exchangeother62d ago kagi ↗

🤖 CVE-2026-59726 (CVSS 10.0): Critical RCE in Ruflo, an open-source agent harness for Claude Code and OpenAI Codex. Unauthenticated attackers can execute arbitrary commands and poison AI agent memory. All versions before 3.16.3 affected. Codenamed "RufRoot". 🔗 https:// thehackernews.com/2026/07/rufl o-mcp-flaw-lets-unauthenticated.html # CVE # RCE # AISecurity # CyberSec

⚠️ PATCH NOW Ruflo, a popular open-source AI agent platform, exposed its control bridge to the whole network with no login. One request runs shell commands (CVE-2026-59726, CVSS 10). Fixed in 3.16.3.

mastodon:infosec-exchangeother61d ago kagi ↗

⚠️ PATCH NOW Ruflo, a popular open-source AI agent platform, exposed its control bridge to the whole network with no login. One request runs shell commands (CVE-2026-59726, CVSS 10). Fixed in 3.16.3. Patch, then audit the agent's memory: a clean redeploy won't clean it. https:// suriq.io/blog/ruflo-rufroot-mc p-bridge-rce-cve-2026-59726 # CVE # infosec # cybersecurity