{"id":"CVE-2026-59726","aliases":["GHSA-c4hm-4h84-2cf3"],"url":"https://o3.security/vulnerability/CVE-2026-59726","summary":"Ruflo: Unauthenticated RCE in MCP bridge default docker-compose deployment","details":"Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns. This issue is fixed in version 3.16.3.","published":"2026-07-09T17:31:20.627Z","modified":"2026-08-12T03:51:22.579801155Z","cvss":{"score":10,"severity":"CRITICAL","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"},"epss":{"score":0.06883,"percentile":0.93547,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/ruvnet/ruflo/commit/d00a0a40cd8bdbca877ac7f675f416bdc69accd1","label":"ruvnet/ruflo@d00a0a4"},"references":[{"type":"WEB","url":"https://github.com/ruvnet/ruflo/releases/tag/v3.16.3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59726.json"},{"type":"ADVISORY","url":"https://github.com/ruvnet/ruflo/security/advisories/GHSA-c4hm-4h84-2cf3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59726"},{"type":"FIX","url":"https://github.com/ruvnet/ruflo/commit/d00a0a40cd8bdbca877ac7f675f416bdc69accd1"},{"type":"FIX","url":"https://github.com/ruvnet/ruflo/pull/2521"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:22.579801155Z"}}