Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
AI Summary
A critical vulnerability in Bifrost, an open-source AI gateway, allows unauthenticated attackers to execute arbitrary commands on the gateway server via a single HTTP request. The flaw, tracked as CVE-2026-90898, affects all versions prior to 2.1.0 when management authentication is disabled by default. Attackers can exploit the /api/mcp/client endpoint to register a stdio-type MCP client, leading to immediate command execution as the gateway process user, potentially exposing stored API keys for LLM providers. A second related vulnerability, CVE-2026-86242, allows unauthenticated registration of a custom plugin from an HTTP URL, resulting in remote code execution or server-side request forgery depending on the build type.
AI-extracted · verify before operational use