Post #4250610
2026-07-30 19:18 UTC
Ruflo's default config shipped with zero auth on its MCP bridge, so anyone could hijack agent tools with one request. Patch closes the door but leaves poisoned memory intact. Updating isn't remediation, it's a false sense of clean.
https://hackread.com/rufroot-vulnerability-attackers-hijack-ruflo-login/
Replies (0)
No replies.