{
    "id": "CVE-2026-59726",
    "published": "2026-07-09 18:16:57",
    "last_modified": "2026-07-10 19:15:15",
    "cvss_score": "10.0",
    "cvss_severity": "CRITICAL",
    "cvss_version": "3.1",
    "cvss_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
    "cwe": "CWE-78",
    "description": "Ruflo is an agent meta-harness for Claude Code and Codex. Prior to 3.16.3, ruflo's default docker-compose deployment exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication, allowing an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provider API keys, and poison AgentDB learning-store patterns. This issue is fixed in version 3.16.3.",
    "epss_score": "0.03019",
    "epss_percentile": "0.87075",
    "kev": 0,
    "kev_due": null,
    "has_exploit": 0,
    "updated_at": "2026-10-10 18:17:54",
    "priority": {
        "rank": 3,
        "label": "In your normal cycle",
        "why": "Critical by CVSS (10), but no sign of active exploitation."
    },
    "products": [],
    "kev_detail": null,
    "exploits": [],
    "refs_list": [
        "https://github.com/ruvnet/ruflo/commit/d00a0a40cd8bdbca877ac7f675f416bdc69accd1",
        "https://github.com/ruvnet/ruflo/pull/2521",
        "https://github.com/ruvnet/ruflo/releases/tag/v3.16.3",
        "https://github.com/ruvnet/ruflo/security/advisories/GHSA-c4hm-4h84-2cf3"
    ]
}