The vulnerability in the AI hosting platform Ruflo allows an unauthenticated attacker to take over the system and corrupt memory, so bad behavior can persist after patching.

July 29, 2026

A maximum-severity vulnerability in the open source AI agent platform Ruflo puts enterprise AI deployments at risk by letting attackers conduct various malicious activities from inside the orchestration framework. The flaw also can leave agents behaviorally compromised even after it's been patched.

Researchers at Noma Security's Noma Labs discovered the flaw, tracked as CVE-2026-59726, in Ruflo, formerly called Claude Flow and which hosts AI agent swarms for Codex and Claude Code, they revealed today. The vulnerability, which received the highest CVSS severity score of 10, allowed them to access the platform without logging in at all, according to Noma Labs.

"The weakness is a lack of authentication coupled with command execution capabilities, enabling complete control over the container and exposure of sensitive credentials," according to details about the flaw posted on OpenCVE.