The CVE record for CVE-2026-58195 was published on 2026-07-17T19:17:17.410Z and has not been modified since then. The NVD entry is currently 8.8 HIGH. This AI-assisted PatchSiren debrief provides an overview of the vulnerability in Agentic-Flow MCP server tools. The vulnerability allows arbitrary OS command execution with the privileges of the MCP server user due to improper interpolation of attacker-infl [truncated]
A critical vulnerability was discovered in Ruflo, an agent meta-harness for Claude Code and Codex. The default docker-compose deployment of Ruflo prior to version 3.16.3 exposed the MCP bridge POST /mcp and POST /mcp/:group endpoints without authentication. This exposure allowed an unauthenticated network attacker to invoke tools/call to terminal_execute, obtain a shell in the bridge container, read provi [truncated]