Skip to content
PERMISSION/PROTOCOL
Back to incident tracker

2026-07-30

HighPrimary

RufRoot (CVE-2026-59726): Unauthenticated RCE and Memory Poisoning in Ruflo Agent Harness Disclosed

Analysis of CVE-2026-59726 (RufRoot), an unauthenticated CVSS 10.0 RCE and memory poisoning vulnerability in the Ruflo Claude Code meta-harness.

RufloTool execution / MCPUnauthenticated API Access and Persistent Instruction PoisoningLocal developer workstation / Centralized multi-agent proxy systems

What happened

An attacker sends an unauthenticated HTTP POST to port 3001, executing terminal tools or injecting system guidelines directly into the agent's memory store.

Why it matters

Full RCE on developer machines, database exfiltration, and persistent agent hijack via memory poisoning.

Missing authorization check

The harness endpoint must require cryptographically-signed authorization tokens from the calling client before executing any tool.

Would PP block it?

Although an attacker can compromise the Ruflo meta-harness over the unauthenticated port, they cannot authorize sensitive system tasks or write operations. Any consequential tool call intercepted by the local PP proxy requires a cryptographically-signed receipt originating from the developer's external security key. Because the attacker cannot forge this signature, the exploit chain is broken.

Incident analysis

Timeline and technical read

Timeline

  1. 2026-07-30

    Noma Security releases primary advisory for CVE-2026-59726 affecting the Ruflo MCP meta-harness.

  2. 2026-07-30

    The Hacker News publishes technical analysis documenting unauthenticated RCE and memory poisoning paths.

Technical breakdown

  • Ruflo bound its default Model Context Protocol (MCP) tool-server on port 3001 to `0.0.0.0` without any token verification.
  • An external attacker scanned the port and called the `execute_shell_command` or `write_file` tools directly.
  • The attacker also modified the SQLite-backed agent memory database, injecting persistent instruction prompts that hijack subsequent sessions.

Authorization boundary

Where the authorization boundary should have been

This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.

If enforced at
Tool-Call Gate, local execution runtime proxy
Still needs
PP does not block unauthenticated network reads on port 3001 that do not trigger state-modifying actions.
Receipt required for
Running terminal commands, reading environment keys, or modifying the agent's memory store

PP's authorization receipts are signed externally — owning the MCP host does not give the attacker the private signing key.

Start small

Put the relevant gate at this action boundary.

This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.

Replay this incident with a signer in the loop