Skip to main content
CyberConfirmedHighDeveloping
10.0

Ruflo MCP tools vulnerability allows unauthenticated remote code execution

A security flaw in Ruflo's Model Context Protocol (MCP) tools leaves 233 deployments exposed to unauthenticated shell command execution. This vulnerability enables attackers to exfiltrate LLM API keys, conversation history, and persistent memory via a single POST request on network-reachable instances.

The Hacker News1 day agoengCredibility 52%View source

Score Breakdown

Mosaic Score10.0
Confidence0.9
Significance0.8
Source credibility0.5
Source

Related signals

8 found