Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
Security

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

The Hacker News · Sep 22, 2026

Back to News
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
Security September 22, 2026

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is

Read original on The Hacker News

Want to stay informed about new business solutions?

Follow us

Ready to build a better digital experience?

We create modern multilingual websites, integrate external services and automate content workflows for growing businesses.