CyberHighConfirmedDeveloping
10.0
Ruflo MCP tools vulnerability allows unauthenticated remote code execution
The Hacker News·1 day ago
A remote code execution vulnerability in Gitea allows users with repository write access to execute arbitrary shell commands as the service account. The exploit is particularly severe because default configurations permit public registration, enabling unauthenticated attackers to gain the necessary write permissions. A public proof-of-concept is available, increasing the risk of immediate exploitation.