Critical unauthenticated RCE patched in ruflo (formerly claude-flow) MCP bridge
CVE-2026-59726 (GHSA-c4hm-4h84-2cf3), a critical unauthenticated remote code execution in the default docker-compose deployment of the ruflo MCP bridge, was published 2026-07-01 at CVSS 10.0. ruflo is the renamed claude-flow agent-orchestration project by the developer rUv. The npm package ruflo is affected below 3.16.3, patched in 3.16.3.
A critical vulnerability in the ruflo MCP bridge was disclosed on
2026-07-01. CVE-2026-59726, tracked as GHSA-c4hm-4h84-2cf3, is an
unauthenticated remote code execution in the project's default
docker-compose deployment, rated CVSS 10.0. The advisory states the npm
package ruflo is affected in versions below 3.16.3 and patched in
3.16.3.
ruflo is the current name of claude-flow, an agent-orchestration harness
by the developer rUv (GitHub ruvnet). The rename is worth stating
plainly because the project is still widely referenced under its old
name: the official MCP Registry record lists it as
io.github.ruvnet/claude-flow, and an older claude-flow npm package
remains published alongside the ruflo package the advisory names.
The vulnerable component is the MCP bridge's docker-compose deployment, not every use of the tool, but the severity and the unauthenticated vector make upgrading to 3.16.3 or later the clear action for anyone running that deployment.
Related servers and clients
- claude-flow - server
How was this verified, and what are the sources?
Published · last verified · confidence 1.00.
- GitHub security advisory GHSA-c4hm-4h84-2cf3 / CVE-2026-59726, "Unauthenticated RCE in ruflo MCP bridge default docker-compose deployment" - critical severity, CVSS 10.0, published 2026-07-01; affects the npm package ruflo below 3.16.3, patched in 3.16.3 - accessed
- ruvnet/ruflo repository - the renamed claude-flow project by the developer rUv; confirms the current name and the npm package ruflo - accessed