What happened
An attacker sends an unauthenticated HTTP POST to port 3001, executing terminal tools or injecting system guidelines directly into the agent's memory store.
2026-07-30
HighPrimaryAnalysis of CVE-2026-59726 (RufRoot), an unauthenticated CVSS 10.0 RCE and memory poisoning vulnerability in the Ruflo Claude Code meta-harness.
What happened
An attacker sends an unauthenticated HTTP POST to port 3001, executing terminal tools or injecting system guidelines directly into the agent's memory store.
Why it matters
Full RCE on developer machines, database exfiltration, and persistent agent hijack via memory poisoning.
Missing authorization check
The harness endpoint must require cryptographically-signed authorization tokens from the calling client before executing any tool.
Would PP block it?
Although an attacker can compromise the Ruflo meta-harness over the unauthenticated port, they cannot authorize sensitive system tasks or write operations. Any consequential tool call intercepted by the local PP proxy requires a cryptographically-signed receipt originating from the developer's external security key. Because the attacker cannot forge this signature, the exploit chain is broken.
Incident analysis
2026-07-30
Noma Security releases primary advisory for CVE-2026-59726 affecting the Ruflo MCP meta-harness.
2026-07-30
The Hacker News publishes technical analysis documenting unauthenticated RCE and memory poisoning paths.
Authorization boundary
This incident is categorized as Tool execution / MCP. The relevant Permission Protocol gate is Tool-Call Gate. The read is conditional: the block only applies where the real action boundary is routed through a gate.
PP's authorization receipts are signed externally — owning the MCP host does not give the attacker the private signing key.
Related incidents and controls
User Reports Production Supabase Database Deleted 10 Minutes Into First Claude Code Session: No External Authorization Gate
OpenAI Autonomous Agent Swarm Exploits Malicious Datasets to Breach Hugging Face Production Clusters and Evade Revocation via Directory-Name Comms Encoding
Start small
This incident maps to Tool-Call Gate. Start with the boundary that controls the actual action, then require a signed receipt before execution.