Source · DiggingBeagle record
Unauthenticated RCE in ruflo MCP bridge default docker-compose deployment
Ruflo GitHub security advisory describing unauthenticated MCP tool invocation, terminal execution, exposed provider keys, AgentDB poisoning and the patched version.
- Published
- Jul 1, 2026
- Accessed
- Sep 19, 2026
- Publisher
- ruflo
- Source type
- vendor_security_advisory
- Version
- GHSA-c4hm-4h84-2cf3 / CVE-2026-59726
Each support, contradiction or context label applies to a cited Claim, not to a whole Case.
Source record
A patched redeploy alone does NOT undo poisoning.
Claim-level citations (5)
- supportsRuflo's default MCP bridge exposed unauthenticated shell execution and agent memory poisoning: The Ruflo GitHub advisory identifies versions before 3.16.3 as affected and 3.16.3 as patched.
Affected versions and Patched versions fields
- supportsRuflo's default MCP bridge exposed unauthenticated shell execution and agent memory poisoning: The Ruflo GitHub advisory tracks the issue as CVE-2026-59726, assigns CVSS 10.0 under v3.1 and lists CWE-78, CWE-306 and CWE-942.
GHSA severity, CVSS vector, CVE ID and weakness fields
- supportsRuflo's default MCP bridge exposed unauthenticated shell execution and agent memory poisoning: Ruflo's shipping Docker Compose deployment exposed the MCP bridge without authentication, and the advisory states that an unauthenticated caller could invoke terminal_execute through the MCP tool path and obtain code execution inside the bridge container.
Description: default docker-compose deployment, unauthenticated POST /mcp and tools/call to terminal_execute
- supportsRuflo's default MCP bridge exposed unauthenticated shell execution and agent memory poisoning: The Ruflo advisory states that successful exploitation could expose provider API keys, allow attacker-controlled swarms to run on victim credentials and persist poisoned patterns into the AgentDB learning store.
Description and impact chain following terminal_execute
- supportsRuflo's default MCP bridge exposed unauthenticated shell execution and agent memory poisoning: Ruflo advises operators of exposed instances to firewall ports 3001 and 27017, rotate provider keys, audit AgentDB for poisoned patterns and audit MongoDB; the advisory warns that redeploying a patched image does not by itself remove poisoned state.
Operator response guidance following the remediation list
Cite this record
DiggingBeagle. “Unauthenticated RCE in ruflo MCP bridge default docker-compose deployment.” Published Jul 1, 2026 · Accessed Sep 19, 2026. https://diggingbeagle.com/sources/unauthenticated-rce-in-ruflo-mcp-bridge-default-docker-compose-deployment/
Citation guidance