Published July 29, 2026 ยท Added July 29, 2026

Noma Labs Discovers Critical Vulnerability in Widely Adopted Open Source AI Agent Platform Ruflo

Noma Security says its researchers found RufRoot, a CVSS 10.0 vulnerability in the open-source Ruflo AI agent platform, exposing unauthenticated MCP tools, shell execution, API keys, conversations, and persistent AI memory until maintainers locked down defaults within 24 hours.

Noma Security says its researchers found RufRoot, a CVSS 10.0 vulnerability in the open-source Ruflo AI agent platform, exposing unauthenticated MCP tools, shell execution, API keys, conversations, and persistent AI memory until maintainers locked down defaults within 24 hours.

Read the original story.

Source: Prnewswire