Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
- ID
- 27378
- Status
- summarized
- Published
- 23 Sep 2026, 12:41 AM
- Fetched
- 23 Sep 2026, 2:56 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 23 Sep 2026, 3:02 AM
- Tags
- Audience
- developersai_agent_usersai_ml_learners
What happened
A CVSS 9.8 unauthenticated RCE flaw (CVE-2026-90898) in Bifrost, an open-source AI gateway routing to 20+ LLM providers, lets attackers execute arbitrary commands via a single POST to /api/mcp/client when management auth is disabled—the default. The official Docker image binds the management API to 0.0.0.0, exposing it outside the container, and since the gateway stores all provider API keys, compromise means full credential theft. Fix is in transports/v2.1.0; v2.0.0 and all 1.6.x through 1.6.11 remain vulnerable, and JFrog advises treating any previously exposed unauthenticated instance as compromised and rotating all keys.
Why it matters
If you run Bifrost in Docker with published ports and default config, your management API is internet-reachable and an attacker can run commands as appuser and steal every LLM provider API key stored on the gateway. Upgrade to transports/v2.1.0 immediately or set governance.auth_config.is_enabled to true; if you ran exposed with auth off, rotate all provider keys now.
Discussion angle
The MCP client registration vector is notable—Bifrost executes the stdio command before any MCP handshake, meaning any tool that accepts MCP client registration needs to treat that endpoint as a code-execution surface, not just a configuration API.