CyberSecurity News
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
AI summary
A critical vulnerability has been discovered in Bifrost, an open-source AI gateway that connects to multiple large language model providers. This flaw allows an attacker without credentials to execute arbitrary commands on the gateway server using a single HTTP request. The vulnerability affects all versions of the Bifrost HTTP transport prior to 2.1.0, but only when management authentication is not enabled. The vulnerability has been assigned a CVSS score of 9.8, indicating a high level of severity. It is identified as CVE-2026-90898. The issue can be mitigated by updating to version 2.1.0 or later of the Bifrost HTTP transport.
Vulnerabilities mentioned
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

