Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
10/10Researchers identified CVE-2026-59726, a maximum-severity vulnerability in Ruflo, allowing unauthenticated attackers to run commands and poison AI memory. This flaw affects AI tools including Anthropic Claude Code and OpenAI Codex, raising significant security concerns in AI-powered platforms.
