Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Ruflo's docker-compose bound port 3001 to 0.0.0.0 by default, publishing an unauthenticated MCP bridge to 233 tools including shell execution, database operations, and memory storage. Noma Labs found that a single HTTP POST reached all of them — shell access, harvested LLM API keys, stored conversations, poisoned agent memory, persistent backdoors — on a platform with 66,500 GitHub stars. Reuven Cohen shipped the patch within 24 hours; the default configuration had been the entire exploit chain.

Severity: Unrated · Category: Supply Chain

Impact: CVE-2026-59726 (CVSS 10.0) · Unauthenticated RCE, API key theft, and AI memory poisoning on all versions before 3.16.3

Source: The Hacker News · Jul 29 2026 · Original source

How Fencio prevents this

The agent trusted a component it had never verified: a package, an extension, a skill, or a server that looked legitimate. When that component changed or was compromised, the agent carried the payload straight into a trusted environment.

Fencio inventories every tool, server, and skill an agent can reach, pins their versions and declared capabilities, and blocks calls when a component starts doing something its manifest never declared, like reading env files or mailing new recipients.

All incidents