CVE-2026-59726 Security Alert: CRITICAL Vulnerability

Urgent: CVE-2026-59726 requires immediate attention.

· 6 min read

Executive Summary

CVE-2026-59726 is a critical unauthenticated remote compromise issue in Ruflo, an agent meta-harness for Claude Code and Codex. In default docker-compose deployments prior to 3.16.3, the MCP bridge exposed POST /mcp and POST /mcp/:group without authentication. A network attacker could invoke tools/call to terminal_execute, gain a shell inside the bridge container, read provider API keys, and poison AgentDB learning-store patterns.

Action is urgent: if you run Ruflo in any reachable environment, treat this as a full container compromise risk and patch immediately to 3.16.3 or later.

Immediate Action

  • Upgrade now to Ruflo 3.16.3 or later. If you cannot patch immediately, take the service offline or remove network exposure to the MCP bridge.
  • Block access to /mcp and /mcp/:group at your reverse proxy, firewall, or ingress until patched.
  • Rotate all secrets that may have been accessible from the bridge container, especially provider API keys and any tokens stored in environment variables or mounted files.
  • Assume compromise if the service was internet-facing: inspect container logs, shell history, and AgentDB entries for unexpected tool calls or poisoned patterns.
  • Rebuild from a clean image after patching; do not rely on a live container you suspect may have been accessed.
  • Check vendor guidance if available: vendor advisory / release notes.

Affected Versions

  • ruflo@<=3.16.2 vulnerable in default docker-compose deployments.
  • ruflo@3.16.3 and later: fixed.
  • If you use a custom deployment, assume exposure unless you have explicitly added authentication or network controls to the MCP bridge.

Resolution Guide

Preferred fix: upgrade Ruflo to the patched release. Use the package manager or image source you already rely on.

# Docker Compose: pin to the fixed tag
services:
  ruflo:
    image: ruflo:3.16.3
# Docker run example
docker pull ruflo:3.16.3
docker stop ruflo
docker rm ruflo
docker run -d --name ruflo ruflo:3.16.3
# npm / yarn / pnpm (if you install Ruflo as a JS package)
npm i ruflo@3.16.3
yarn add ruflo@3.16.3
pnpm add ruflo@3.16.3
# pip / pipx (if published as a Python package)
pip install --upgrade ruflo==3.16.3
pipx upgrade ruflo
# Maven / Gradle (if consumed as a Java dependency)
# Maven
mvn versions:use-latest-releases -Dincludes=TODO_GROUP_ID:ruflo

# Gradle
./gradlew dependencyUpdates
# then pin to TODO_GROUP_ID:ruflo:3.16.3
# apt / yum (if your distro packages Ruflo)
sudo apt-get update && sudo apt-get install --only-upgrade ruflo
sudo yum update ruflo

Hardening while you patch:

# Example reverse-proxy rule: deny MCP endpoints unless authenticated
location ~ ^/mcp(/.*)?$ {
    deny all;
    return 403;
}
# Example Docker Compose hardening
services:
  ruflo:
    ports: []
    expose:
      - "TODO_INTERNAL_ONLY_PORT"
    networks:
      - internal
    environment:
      - MCP_AUTH_REQUIRED=true
      - DISABLE_TERMINAL_EXECUTE=true

Minimal code fix pattern: ensure the bridge rejects unauthenticated requests before any tool dispatch.

// Pseudocode patch
app.post("/mcp", requireAuth, handleMcp);
app.post("/mcp/:group", requireAuth, handleMcpGroup);

// Or inside the handler:
if (!request.user) {
  return response.status(401).json({ error: "authentication required" });
}

Detection & Verification

Check your version first. If you use Docker:

docker inspect ruflo --format '{{.Config.Image}}'
docker exec -it ruflo ruflo --version

Look for exposed endpoints:

curl -i http://YOUR_HOST:YOUR_PORT/mcp
curl -i http://YOUR_HOST:YOUR_PORT/mcp/default

If these respond without authentication, you are likely vulnerable.

Search deployment files:

grep -RInE '(/mcp|terminal_execute|AgentDB|ruflo)' .

Check logs for abuse: look for unexpected tools/call requests, terminal_execute invocations, new shell sessions, or unusual AgentDB writes.

Verify the fix:

# Confirm the patched version
ruflo --version

# Confirm endpoints now require auth or are unreachable
curl -i http://YOUR_HOST:YOUR_PORT/mcp
# Expect 401, 403, or no route

# Confirm container image tag
docker inspect ruflo --format '{{.Config.Image}}'
# Expect ruflo:3.16.3 or later

Risk and Impact

This flaw can hand an attacker a shell inside the bridge container without credentials, which is enough to read provider API keys and pivot into connected AI workflows. Because the MCP bridge can execute terminal actions, the blast radius includes code execution, secret theft, and tampering with stored learning data that may influence future agent behavior.

For solo developers and small teams, the practical impact is severe: one exposed service can expose your model credentials, automation pipelines, and any downstream systems that trust Ruflo’s outputs. Treat this as a high-priority incident even if you have not seen signs of exploitation.

Keep reading