[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":54,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":61,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":67,"vulnerability-29727":74},[4,15,21,27,33,39,44],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",{"title":45,"slug":46,"text":47,"link":48,"external":49,"targets":50,"cta":53,"variant":13,"campaign_id":46},"Office Hours #11 - Compliance cycle survey","office-hours-11","[Live Office Hours, Wed Sept 16] Continuous compliance evidence: from automated tools or tired humans?","https:\u002F\u002Fzoom.us\u002Fwebinar\u002Fregister\u002F5117815316917\u002FWN_FLMs2-vyQbCTB67guMJH-Q",true,[51,52],"\u002Finsights\u002Fcompliance-cycles-survey","\u002Finsights","Save your spot",["Island",55],{"key":56,"params":57,"result":59},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":58},"{}",{"head":60},{},["Island",62],{"key":63,"params":64,"result":65},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":58},{"head":66},{},["Island",68],{"key":69,"params":70,"result":72},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":71},"{\"text-color\":\"gray\"}",{"head":73},{},{"id":75,"detectable_with":76,"vuln_details":83,"vuln_id":101,"name":102,"published":103,"updated":84},29727,{"tool":77,"engine":80},{"id":78,"name":79},1,"Network Scanner",{"id":81,"name":82},2,"Nuclei",{"id":75,"codename":84,"description":84,"severity":85,"risk_description":86,"public_description":87,"public_recommendation":88,"recommendation":84,"references":89,"cvssv3":93,"epss_score":94,"epss_percentile":95,"cve":96,"in_cisa_catalog":9,"date":98,"software_type":84,"vendor":99,"product":100,"ptt_exploit_capabilities":84},null,"critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","ruflo MCP bridge (\u003C 3.16.3) in its default docker-compose deployment exposes POST \u002Fmcp with no authentication and binds to all interfaces (0.0.0.0:3001). The executeTool() function has no server-side deny list for dangerous tools, allowing an unauthenticated attacker to invoke tools\u002Fcall with ruflo__terminal_execute, which runs execSync(command) on attacker-supplied input. This yields arbitrary command execution as the node user (uid 1000) inside the bridge container. The blocklist (AUTOPILOT_BLOCKED_PATTERNS + isBlockedTool()) is enforced only in the autopilot SSE handler; POST \u002Fmcp and POST \u002Fmcp\u002F:group bypass it entirely.","Upgrade ruflo to version 3.16.3 or later which adds DANGEROUS_TOOLS gate in executeTool(), bearer auth middleware (MCP_AUTH_TOKEN), loopback bind by default (BIND_HOST=127.0.0.1), and MCP_ENABLE_TERMINAL opt-in. As interim mitigation, firewall port 3001 and set MCP_AUTH_TOKEN in docker-compose.yml.",[90,91,92],"https:\u002F\u002Fgithub.com\u002Fruvnet\u002Fruflo\u002Fsecurity\u002Fadvisories\u002FGHSA-c4hm-4h84-2cf3","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-59726","https:\u002F\u002Fwww.pruva.dev\u002Freproductions\u002FREPRO-2026-00315",9.8,0.06883,0.93688,[97],"CVE-2026-59726","2026-07-09T00:00:00Z","ruvnet","ruflo","NETSCAN-NUCLEI-CVE-CVE-2026-59726","ruflo MCP Bridge - Unauthenticated RCE via terminal_execute","2026-09-15T00:00:00Z"]