Ruflo patches critical CVE-2026-59726 that lets unauthenticated attackers run commands on exposed AI agent servers

Ruflo fixed a critical flaw that could let anyone on the network take control of exposed self-hosted AI agent servers without logging in. The issue, CVE-2026-59726, affects the open source Ruflo platform (formerly Claude Flow) via an unauthenticated POST /mcp endpoint in default docker-compose deployments, where the MCP bridge on port 3001 is bound to all interfaces. Attackers could execute commands in the bridge container, access API keys, spawn agent swarms, and poison the platform’s shared memory and output behavior. The flaw is patched in Ruflo 3.16.3.
Why it matters: Organizations self-hosting Ruflo could be exposed to remote takeover, secret theft, and tampering with AI-driven actions and outputs. Users should update to Ruflo 3.16.3 immediately and check whether port 3001 or the MCP bridge was exposed to untrusted networks.

Sources

Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms
Ionut Arghire 2026.07.30 100% relevant
This article appears to be the first tracked report establishing the disclosure, impact, CVE, default exposure conditions, and patched version for the Ruflo vulnerability.
← Back to all stories