hacker-news · Crawled Sep 22, 2026

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

1 Malware 3 CVEs
Read original article ↗

AI Summary

A critical vulnerability in Bifrost, an open-source AI gateway, allows unauthenticated attackers to execute arbitrary commands on the gateway server via a single HTTP request. The flaw, tracked as CVE-2026-90898, affects all versions prior to 2.1.0 when management authentication is disabled by default. Attackers can exploit the /api/mcp/client endpoint to register a stdio-type MCP client, leading to immediate command execution as the gateway process user, potentially exposing stored API keys for LLM providers. A second related vulnerability, CVE-2026-86242, allows unauthenticated registration of a custom plugin from an HTTP URL, resulting in remote code execution or server-side request forgery depending on the build type.

AI-extracted · verify before operational use

Extracted Entities 4 found

MITRE ATT&CK TTPs 3 techniques