VulnWatch VulnWatch
← Back to dashboard
Unknown rss_thehackernews · rss_ba859ad0f6f0f955274dc328cf9d5889

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

Published Sep 22, 2026

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.

The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is

Affected AI Products

llm
Get the weekly digest. Every Monday: top AI security stories of the week. Free.