CVSS 10.0 RufRoot Vulnerability Allowed Attackers to Hijack Ruflo Without Login

Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk.

This article has been indexed from Hackread – Cybersecurity News, Data Breaches, AI and More

Read the original article: