Patch-Resistant Ruflo Flaw Can Unleash Malicious AI Agent Swarms
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
A maximum-severity (CVSS 10) vulnerability, CVE-2026-59726, was discovered in Ruflo, an open source AI agent hosting platform for Codex and Claude Code. The flaw stems from unauthenticated MCP bridge endpoints exposed by default in Ruflo's docker-compose deployment, allowing attackers to gain full remote code execution with a single HTTP request, access stored API keys and user conversations, and launch rogue AI agent swarms. Most critically, attackers can tamper with the platform's AgentDB memory store, planting persistent behavioral instructions that influence AI responses even after patching. Noma Labs disclosed the flaw on June 30; Ruflo patched within 24 hours by requiring explicit opt-in for public exposure. However, organizations must also rotate compromised credentials, audit AI memory for tampering, and rebuild containers from clean images, as patching alone cannot undo memory corruption.