Breaches  › Other  › CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijac…
medium · other · Disclosed Jul 29, 2026

CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In

Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.

Original Disclosure
https://hackread.com/rufroot-vulnerability-attackers-hijack…
Read original
Severity
medium
Sector
other
Disclosure date
July 29, 2026
Indexed
12 hours, 27 minutes ago