Breaches  › Other  › Ruflo fixed a CVSS 10.0 flaw that exposed its MCP…
medium · other · Disclosed Jul 29, 2026

Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication,

Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.

Original Disclosure
https://hackread.com/rufroot-vulnerability-attackers-hijack…
Read original
Severity
medium
Sector
other
Disclosure date
July 29, 2026
Indexed
15 hours, 1 minute ago