CVSS 10.0 RufRoot Vulnerability Allowed Attackers to Hijack Ruflo Without Login

https://hackread.com/wp-content/uploads/2026/07/rufroot-vulnerability-attackers-hijack-ruflo-login.jpg

A vulnerable Ruflo deployment could be taken over with a single network request, without a username, password, or action from an authorized user, according to research published by Noma Security.

Security Products & Services

The flaw, named RufRoot and tracked as CVE-2026-59726, received the maximum CVSS score of 10.0. It affects Ruflo versions before 3.16.3 when deployed using the project’s previous default Docker Compose configuration.

Ruflo, formerly known as Claude Flow, is an open-source platform that coordinates AI agents, gives them access to tools, and maintains information between sessions. It works as a supporting layer for coding agents such as Claude Code and Codex. The vulnerability is in Ruflo, not in Claude Code or Codex themselves.

No Login Required to Access Agent Tools

The previous default configuration exposed Ruflo’s Model Context Protocol (MCP) bridge to the network without authentication. MCP allows AI systems to call external tools, including tools...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE