Security researchers at Noma Security disclosed a maximum-severity (CVSS 10) vulnerability, dubbed “RufRoot” (CVE-2026-59726), in Ruflo (formerly Claude Flow), an open-source AI agent orchestration platform. The flaw let unauthenticated attackers send a single HTTP request to the platform’s exposed MCP Bridge to achieve full remote code execution, steal AI provider API credentials, and tamper with stored agent memory in ways that can persist even after patching.
Noma reported the issue on June 30, 2026, and Ruflo shipped a default-lockdown fix within 24 hours. All versions of the project before 3.16.3 were affected.