HackerFeeds

CyberSecurity News

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

The Hacker News
· September 22, 2026

AI summary

A critical vulnerability has been discovered in Bifrost, an open-source AI gateway that connects to multiple large language model providers. This flaw allows an attacker without credentials to execute arbitrary commands on the gateway server using a single HTTP request. The vulnerability affects all versions of the Bifrost HTTP transport prior to 2.1.0, but only when management authentication is not enabled. The vulnerability has been assigned a CVSS score of 9.8, indicating a high level of severity. It is identified as CVE-2026-90898. The issue can be mitigated by updating to version 2.1.0 or later of the Bifrost HTTP transport.

Vulnerabilities mentioned

Read the full article at The Hacker Newsthehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.