CVE-2026-59726: Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment
Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminalexecute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns. This issue is fixed in version 3.16.3.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
rufloto a version that resolves this vulnerability.Fixed in 3.16.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59726?
The severity of CVE-2026-59726 is critical with a score of 10.
How do I fix CVE-2026-59726?
To fix CVE-2026-59726, upgrade Ruflo to version 3.16.3 or later.
What kind of attack does CVE-2026-59726 enable?
CVE-2026-59726 enables unauthenticated remote code execution (RCE) through the MCP bridge endpoints.
Which software is affected by CVE-2026-59726?
CVE-2026-59726 affects Ruflo prior to version 3.16.3.
What type of vulnerability is CVE-2026-59726 classified as?
CVE-2026-59726 is classified as an OS Command Injection vulnerability.