Critical Bifrost AI Gateway Flaw Allowed Unauthenticated Remote Code Execution
A critical vulnerability (CVE-2026-90898, CVSS 9.8) in the Bifrost open-source AI gateway allowed attackers to execute arbitrary commands with a single unauthenticated HTTP POST request to its MCP management API. Discovered by Yuval Moravchick at JFrog Security Research, the flaw stemmed from management authentication being disabled by default and the official Docker image binding the API to 0.0.0.0, making it publicly reachable. Exploiting the stdio transport type, an attacker could register a malicious MCP client that caused Bifrost to spawn any specified shell command as its own process user. This exposed environment variables containing API keys for all configured LLM providers, including OpenAI, Anthropic, and Google. The issue has been patched in transports/v2.1.0, and users running versions 2.0.x or 1.6.x are urged to update immediately.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in