Noma Security says its researchers found RufRoot, a CVSS 10.0 vulnerability in the open-source Ruflo AI agent platform, exposing unauthenticated MCP tools, shell execution, API keys, conversations, and persistent AI memory until maintainers locked down defaults within 24 hours.
Noma Labs Discovers Critical Vulnerability in Widely Adopted Open Source AI Agent Platform Ruflo
Noma Security says its researchers found RufRoot, a CVSS 10.0 vulnerability in the open-source Ruflo AI agent platform, exposing unauthenticated MCP tools, shell execution, API keys, conversations, and persistent AI memory until maintainers locked down defaults within 24 hours.
Source: Prnewswire