importantSYS.SOURCE: The Hacker News• 2026-09-22T22:11:12+05:30
Critical Bifrost AI Gateway Vulnerability Allows Unauthenticated Command Execution
A critical vulnerability (CVE-2026-90898) in the Bifrost AI gateway allows unauthenticated attackers to execute arbitrary commands on the server via a single HTTP request when management authentication is disabled. The flaw affects all versions before 2.1.0 and requires immediate upgrades or configuration changes to mitigate risks.
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.
The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is
*** END OF TRANSMISSION ***