Forkast reports that RufRoot in the open-source Ruflo AI agent platform let unauthenticated attackers use exposed MCP tools for remote code execution and poison AgentDB’s persistent memory, meaning a software patch alone may not remove planted instructions.
RufRoot: Patching Doesn’t Undo Poisoning — The MCP Flaw That Persists Inside AI Memory
Forkast reports that RufRoot in the open-source Ruflo AI agent platform let unauthenticated attackers use exposed MCP tools for remote code execution and poison AgentDB's persistent memory, meaning a software patch alone may not remove planted instructions.
Source: Forkast