AI Weekly Malaysia

Back to items Summaries

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

ID
27378
Status
summarized
Published
23 Sep 2026, 12:41 AM
Fetched
23 Sep 2026, 2:56 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
23 Sep 2026, 3:02 AM
Tags
Audience
developersai_agent_usersai_ml_learners

What happened

A CVSS 9.8 unauthenticated RCE flaw (CVE-2026-90898) in Bifrost, an open-source AI gateway routing to 20+ LLM providers, lets attackers execute arbitrary commands via a single POST to /api/mcp/client when management auth is disabled—the default. The official Docker image binds the management API to 0.0.0.0, exposing it outside the container, and since the gateway stores all provider API keys, compromise means full credential theft. Fix is in transports/v2.1.0; v2.0.0 and all 1.6.x through 1.6.11 remain vulnerable, and JFrog advises treating any previously exposed unauthenticated instance as compromised and rotating all keys.

Why it matters

If you run Bifrost in Docker with published ports and default config, your management API is internet-reachable and an attacker can run commands as appuser and steal every LLM provider API key stored on the gateway. Upgrade to transports/v2.1.0 immediately or set governance.auth_config.is_enabled to true; if you ran exposed with auth off, rotate all provider keys now.

Discussion angle

The MCP client registration vector is notable—Bifrost executes the stdio command before any MCP handshake, meaning any tool that accepts MCP client registration needs to treat that endpoint as a code-execution surface, not just a configuration API.

Top