SOURCE-LINKED INTELLIGENCE
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is
Read original source ↗ Open in workspace
- recordType
- article
- region
- Global
Evidence & attribution
- The Hacker News · 2026-09-22T16:41:12.000Z
First collected: 2026-09-22T22:51:10.705Z. This is not the publication date.