CVE-2026-59726 Security Alert: CRITICAL Vulnerability
Urgent: CVE-2026-59726 requires immediate attention.
· 6 min read
Executive Summary
CVE-2026-59726 is a critical unauthenticated remote compromise issue in Ruflo, an agent meta-harness for Claude Code and Codex. In default docker-compose deployments prior to 3.16.3, the MCP bridge exposed POST /mcp and POST /mcp/:group without authentication. A network attacker could invoke tools/call to terminal_execute, gain a shell inside the bridge container, read provider API keys, and poison AgentDB learning-store patterns.
Action is urgent: if you run Ruflo in any reachable environment, treat this as a full container compromise risk and patch immediately to 3.16.3 or later.
Immediate Action
- Upgrade now to Ruflo
3.16.3or later. If you cannot patch immediately, take the service offline or remove network exposure to the MCP bridge. - Block access to
/mcpand/mcp/:groupat your reverse proxy, firewall, or ingress until patched. - Rotate all secrets that may have been accessible from the bridge container, especially provider API keys and any tokens stored in environment variables or mounted files.
- Assume compromise if the service was internet-facing: inspect container logs, shell history, and AgentDB entries for unexpected tool calls or poisoned patterns.
- Rebuild from a clean image after patching; do not rely on a live container you suspect may have been accessed.
- Check vendor guidance if available: vendor advisory / release notes.
Affected Versions
ruflo@<=3.16.2vulnerable in defaultdocker-composedeployments.ruflo@3.16.3and later: fixed.- If you use a custom deployment, assume exposure unless you have explicitly added authentication or network controls to the MCP bridge.
Resolution Guide
Preferred fix: upgrade Ruflo to the patched release. Use the package manager or image source you already rely on.
# Docker Compose: pin to the fixed tag
services:
ruflo:
image: ruflo:3.16.3
# Docker run example
docker pull ruflo:3.16.3
docker stop ruflo
docker rm ruflo
docker run -d --name ruflo ruflo:3.16.3
# npm / yarn / pnpm (if you install Ruflo as a JS package)
npm i ruflo@3.16.3
yarn add ruflo@3.16.3
pnpm add ruflo@3.16.3
# pip / pipx (if published as a Python package)
pip install --upgrade ruflo==3.16.3
pipx upgrade ruflo
# Maven / Gradle (if consumed as a Java dependency)
# Maven
mvn versions:use-latest-releases -Dincludes=TODO_GROUP_ID:ruflo
# Gradle
./gradlew dependencyUpdates
# then pin to TODO_GROUP_ID:ruflo:3.16.3
# apt / yum (if your distro packages Ruflo)
sudo apt-get update && sudo apt-get install --only-upgrade ruflo
sudo yum update ruflo
Hardening while you patch:
# Example reverse-proxy rule: deny MCP endpoints unless authenticated
location ~ ^/mcp(/.*)?$ {
deny all;
return 403;
}
# Example Docker Compose hardening
services:
ruflo:
ports: []
expose:
- "TODO_INTERNAL_ONLY_PORT"
networks:
- internal
environment:
- MCP_AUTH_REQUIRED=true
- DISABLE_TERMINAL_EXECUTE=true
Minimal code fix pattern: ensure the bridge rejects unauthenticated requests before any tool dispatch.
// Pseudocode patch
app.post("/mcp", requireAuth, handleMcp);
app.post("/mcp/:group", requireAuth, handleMcpGroup);
// Or inside the handler:
if (!request.user) {
return response.status(401).json({ error: "authentication required" });
}
Detection & Verification
Check your version first. If you use Docker:
docker inspect ruflo --format '{{.Config.Image}}'
docker exec -it ruflo ruflo --version
Look for exposed endpoints:
curl -i http://YOUR_HOST:YOUR_PORT/mcp
curl -i http://YOUR_HOST:YOUR_PORT/mcp/default
If these respond without authentication, you are likely vulnerable.
Search deployment files:
grep -RInE '(/mcp|terminal_execute|AgentDB|ruflo)' .
Check logs for abuse: look for unexpected tools/call requests, terminal_execute invocations, new shell sessions, or unusual AgentDB writes.
Verify the fix:
# Confirm the patched version
ruflo --version
# Confirm endpoints now require auth or are unreachable
curl -i http://YOUR_HOST:YOUR_PORT/mcp
# Expect 401, 403, or no route
# Confirm container image tag
docker inspect ruflo --format '{{.Config.Image}}'
# Expect ruflo:3.16.3 or later
Risk and Impact
This flaw can hand an attacker a shell inside the bridge container without credentials, which is enough to read provider API keys and pivot into connected AI workflows. Because the MCP bridge can execute terminal actions, the blast radius includes code execution, secret theft, and tampering with stored learning data that may influence future agent behavior.
For solo developers and small teams, the practical impact is severe: one exposed service can expose your model credentials, automation pipelines, and any downstream systems that trust Ruflo’s outputs. Treat this as a high-priority incident even if you have not seen signs of exploitation.