Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
4 Articles
4 Articles
Bifrost AI Gateway Flaw Allows Hackers to Run Rogue Commands
A critical vulnerability in Bifrost is putting AI infrastructure at risk. The open-source gateway, which routes requests to more than 20 LLM providers, allows unauthenticated attackers to run arbitrary commands on servers. Researchers disclosed the flaw on September 22, 2026, with a patch already available. The vulnerability, tracked as CVE-2026-90898, carries a CVSS score of […]
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is
Coverage Details
Bias Distribution
- There is no tracked Bias information for the sources covering this story.
Factuality
To view factuality data please Upgrade to Premium






