RufRoot is a critical unauthenticated remote code execution vulnerability in Ruflo affecting versions prior to 3.16.3 when deployed with the default Docker Compose configuration. The flaw is caused by the MCP bridge exposing the POST /mcp and POST /mcp/:group endpoints without authentication, allowing any network-reachable attacker to invoke tool execution through the bridge. In particular, an attacker can call terminal execution functionality via the MCP tool interface, obtain shell access inside the bridge container, access sensitive runtime material such as provider API keys, and modify Ruflo’s persistent AgentDB learning store. The vulnerable component is the MCP bridge, which serves as the control path for tool calls, agent actions, and memory operations in Ruflo deployments.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
40 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated remote command execution vulnerability in Ruflo's MCP bridge caused by exposing the POST /mcp endpoint without authentication in default self-hosted docker-compose deployments.
A maximum-severity unauthenticated remote code execution vulnerability in the Ruflo open-source AI agent platform that can expose API keys, stored conversations, and enable persistent AI memory tampering ('memory poisoning') even after patching.
A maximum-severity unauthenticated remote code execution vulnerability in Ruflo caused by an unauthenticated MCP bridge exposed to the network by default, allowing attackers to invoke powerful tools including shell command execution.
A critical unauthenticated remote command execution vulnerability in Ruflo’s MCP Bridge that can allow full compromise of AI agent environments and associated data stores.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.