/Vulnerability Library

ruflo MCP Bridge - Unauthenticated RCE via terminal_execute

CVE-2026-59726
Verified

Description

ruflo MCP bridge (< 3.16.3) in its default docker-compose deployment exposes POST /mcp with no authentication and binds to all interfaces (0.0.0.0:3001). The executeTool() function has no server-side deny list for dangerous tools, allowing an unauthenticated attacker to invoke tools/call with ruflo__terminal_execute, which runs execSync(command) on attacker-supplied input. This yields arbitrary command execution as the node user (uid 1000) inside the bridge container. The blocklist (AUTOPILOT_BLOCKED_PATTERNS + isBlockedTool()) is enforced only in the autopilot SSE handler; POST /mcp and POST /mcp/:group bypass it entirely.

Severity

Critical

CVSS Score

9.8

Exploit Probability

3%

Affected Product

ruflo

Published Date

September 15, 2026

Template Author

dhiyaneshdk

CVE-2026-59726.yaml
9.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-59726
CWE ID:
cwe-78

References

https://github.com/ruvnet/ruflo/security/advisories/GHSA-c4hm-4h84-2cf3https://nvd.nist.gov/vuln/detail/CVE-2026-59726https://www.pruva.dev/reproductions/REPRO-2026-00315

Remediation Steps

Upgrade ruflo to version 3.16.3 or later which adds DANGEROUS_TOOLS gate in executeTool(), bearer auth middleware (MCP_AUTH_TOKEN), loopback bind by default (BIND_HOST=127.0.0.1), and MCP_ENABLE_TERMINAL opt-in. As interim mitigation, firewall port 3001 and set MCP_AUTH_TOKEN in docker-compose.yml.