
A 10.0 IN THE TOOL THAT ORCHESTRATES CLAUDE CODE AND CODEX. ONE HTTP REQUEST, FULL SHELL. CVE-2026-59726, nicknamed RufRoot. It hit Ruflo, an agent harness with 66,000 GitHub stars. How simple it was: - Default deployment exposed the MCP bridge to the whole network - 233 tools behind it, zero authentication - One of them runs shell commands - A single POST request gets you inside What the attacker walks out with: - Provider API keys - Every stored conversation - Write access to the agent's memory That last one is the problem. Keys get rotated. Containers get rebuilt. Poisoned entries in an agent's memory stay after the patch, because they are data, not code. You fixed the door. What walked through it is still in the filing cabinet. The takeaway worth saving: Patch the path, then audit the memory. Agent systems have two attack surfaces: the code that runs them, and the store they learn from. Incident response built for servers only covers the first. Fixed in 24 hours, version 3.16.3. Good vendor response. The mistake behind it was the ordinary one: bind to all interfaces, assume nobody is looking. If your agent stack was compromised for a week, would you know what it learned?
Post summary
CVE-2026-59726 permitted unauthenticated RCE in the Ruflo agent harness via a single POST request, enabling attackers to steal API keys and data. The vulnerability was actively exploited and patched within 24 hours in version 3.16.3.



















