Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
Summary
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is
Lotu Radar provides attributed news summaries and links to the original publisher. Full reporting and copyright remain with the source.