MCPNews

The Model Context Protocol ecosystem, verified

Current spec 2026-07-28

Critical unauthenticated RCE patched in ruflo (formerly claude-flow) MCP bridge

CVE-2026-59726 (GHSA-c4hm-4h84-2cf3), a critical unauthenticated remote code execution in the default docker-compose deployment of the ruflo MCP bridge, was published 2026-07-01 at CVSS 10.0. ruflo is the renamed claude-flow agent-orchestration project by the developer rUv. The npm package ruflo is affected below 3.16.3, patched in 3.16.3.

A critical vulnerability in the ruflo MCP bridge was disclosed on 2026-07-01. CVE-2026-59726, tracked as GHSA-c4hm-4h84-2cf3, is an unauthenticated remote code execution in the project's default docker-compose deployment, rated CVSS 10.0. The advisory states the npm package ruflo is affected in versions below 3.16.3 and patched in 3.16.3.

ruflo is the current name of claude-flow, an agent-orchestration harness by the developer rUv (GitHub ruvnet). The rename is worth stating plainly because the project is still widely referenced under its old name: the official MCP Registry record lists it as io.github.ruvnet/claude-flow, and an older claude-flow npm package remains published alongside the ruflo package the advisory names.

The vulnerable component is the MCP bridge's docker-compose deployment, not every use of the tool, but the severity and the unauthenticated vector make upgrading to 3.16.3 or later the clear action for anyone running that deployment.

Related servers and clients

How was this verified, and what are the sources?

Published · last verified · confidence 1.00.

  1. GitHub security advisory GHSA-c4hm-4h84-2cf3 / CVE-2026-59726, "Unauthenticated RCE in ruflo MCP bridge default docker-compose deployment" - critical severity, CVSS 10.0, published 2026-07-01; affects the npm package ruflo below 3.16.3, patched in 3.16.3 - accessed
  2. ruvnet/ruflo repository - the renamed claude-flow project by the developer rUv; confirms the current name and the npm package ruflo - accessed

← All news