URL has been copied successfully!
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link