HIGH
Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms via MCP Bridge
SecurityWeek reports a critical flaw in Ruflo that lets unauthenticated attackers send HTTP requests to an exposed endpoint and execute commands inside the product’s MCP bridge container.
The bug effectively allows remote code execution against infrastructure used to orchestrate AI agent “swarms.” No CVE identifier or patch status was included in the available summary.