CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
Wed Jul 29 2026
Vulnerability
hackread.com
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.