RufRoot: Patching Doesn’t Undo Poisoning — The MCP Flaw That Persists Inside AI Memory
A maximum-severity vulnerability in Ruflo, an open-source AI agent orchestration platform with more than 67,000 GitHub stars, allowed unauthenticated attackers to gain full remote code execution — and then poison the platform’s persistent AI memory in a way that a software patch alone cannot undo. The flaw, tracked as CVE-2026-59726 (CVSS 10.0) and codenamed RufRoot…