Vulnerability in Ruflo AI Platform Exposes Enterprises to Attack Risks
A serious security vulnerability in Ruflo, an open-source AI agent platform, poses significant risks to enterprises by enabling attackers to hijack AI operations through an exposed Model Context Protocol (MCP) bridge. This flaw, categorized as CVE-2026-59726 and referred to as RufRoot, has a maximum CVSS score of 10.0 and impacts versions of Ruflo prior to 3.16.3, according to research by Noma Security.
The vulnerability allows attackers to execute arbitrary code, steal large language model (LLM) API keys, access user conversations, and manipulate the platform’s AI memory, all initiated through a single HTTP request. The researchers pinpoint the issue to an unauthenticated MCP Bridge that is enabled by default, which grants unprotected access to crucial AI interaction tools within enterprise systems.
As detailed by Noma Security, the MCP Bridge operates as an Express.js server managing tool invocations made by AI agents. It exposes 233 tools encompassing shell access, database commands, agent management, and memory storage. The critical endpoint of this bridge accepts invocations without any authentication, which is where the vulnerability lies.
Single Request Leads to Total Control
Researchers demonstrated that a simple command through Ruflo’s terminal_execute tool allows full command execution within the container with just one HTTP request. This type of access could enable an attacker to occupy a central role in the system’s operations. By reaching the /mcp endpoint, attackers can gain unauthorized access to the underlying resources, creating a severe security breach.
During their testing, the researchers successfully enumerated available tools, extracted LLM provider API keys from environment variables, deployed malicious AI agent swarms, and fetched user conversations stored in MongoDB. They also simulated AI memory poisoning, where harmful entries were inserted into the AgentDB pattern store, thereby instructing future AI actions according to the attacker’s preferences.
Every phase of their attack methodology was validated against a Ruflo deployment on AWS EC2, indicating the viability of these exploitative strategies in real-world scenarios.
Wider Implications for MCP Security
While the flaw is specific to Ruflo, it serves as a wake-up call about broader vulnerabilities associated with AI orchestration platforms and MCP infrastructures. Amit Jena, AI Development Manager at Kanerika, explained that the pace of MCP adoption has often superseded the security defaults incorporated into many orchestration tools, leading to a false sense of security about network boundaries protecting these assets.
“Platforms shipped quickly, prioritizing ease of setup over robust authentication measures,” Jena noted. This oversight becomes critical as these tools operate on servers connected to corporate networks.
Jena emphasized that memory poisoning isn't bounded to one product. “Any platform that provides a persistent, writeable memory store must treat that store as a security boundary,” he stated, stressing the necessity for rigorous control over who can manipulate this memory and whether it can be differentiated from legitimate system-generated data. Currently, many systems are failing to uphold these standards.
Addressing the Vulnerability
Noma Security responsibly disclosed the vulnerability to Ruflo, which acted quickly, issuing fixes within hours alongside a public advisory. The patch alters the MCP Bridge to bind to the loopback interface by default and limits exposure if administrators do not configure authentication correctly.
Organizations still utilizing Ruflo are advised to close firewall access to the relevant ports immediately, rotate all LLM API keys, inspect the AgentDB for malicious entries since a patch alone won’t erase potential memory poisoning, and check MongoDB for signs of unauthorized changes.
To bolster security, Jena recommended a reevaluation of deployment and management practices for AI orchestration platforms. If a component can carry out shell commands or query databases, it should be treated with the same authentication level and logging protocol as any other critical system resource. He further advocated for periodic audits of the tools exposed through AI agent deployments, distinctive oversight of persistent AI memory compared to software updates, and cautious management of LLM provider credentials after any suspected breaches.