Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: self-hosted-ai (1 article)Clear

Critical Bifrost AI gateway flaw lets unauthenticated attackers run commands and steal provider keys

JFrog disclosed a critical flaw in Bifrost, an open-source AI gateway routing to over twenty LLM providers, that lets an unauthenticated attacker run arbitrary commands on the gateway with a single HTTP request. Tracked as CVE-2026-90898 and rated 9.8, it affects all Bifrost HTTP transport versions before 2.1.0 when management authentication is disabled, which is the default. An attacker registers a stdio-type MCP client through an unauthenticated POST to /api/mcp/client, and Bifrost runs the command immediately, before any handshake, as the gateway user. Because the gateway stores API keys for every connected provider, command execution also exposes those credentials, and the official Docker image binds its management API to all interfaces.

Check
Upgrade Bifrost to transports 2.1.0, enable management authentication, keep the management listener off untrusted networks, and rotate any provider keys the gateway held.
Affected
Bifrost gateways before 2.1.0 with default disabled management auth let an unauthenticated attacker run commands and read every connected provider API key.
Fix
Update to 2.1.0, set governance.auth_config.is_enabled to true with strong credentials, avoid publishing the management port, and treat exposed instances as compromised.