CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In
Ruflo fixed a CVSS 10.0 flaw that exposed its MCP bridge without any authentication, putting AI provider keys, stored chats and persistent agent memory at risk. Continue reading CVSS 10.0 RufRoot Flaw Allowed Attackers to Hijack Ruflo Without Logging In