By Interestana AI Editorial — AI-drafted, human-overseen. How we report
Critical Bifrost AI Gateway Flaw Allows Unauthenticated Command Execution

A critical vulnerability, tracked as CVE-2026-90898, has been identified in Bifrost, an open-source AI gateway designed to route requests to over 20 different Large Language Model (LLM) providers. This flaw permits an unauthenticated attacker to execute arbitrary commands on the Bifrost gateway server through a single HTTP request, bypassing standard authentication mechanisms. The vulnerability carries a CVSS score of 9.8, indicating a critical severity level. All versions of the Bifrost HTTP transport prior to version 2.1.0 are affected by this vulnerability, specifically when management authentication is enabled. The Bifrost gateway serves as a crucial component in many AI infrastructure setups, simplifying the process of interacting with various LLM services by providing a unified interface. Its ability to connect to numerous LLM providers means that a compromise of the gateway could potentially expose sensitive data or allow for malicious actions across multiple AI services that rely on it. The open-source nature of Bifrost, while promoting transparency and community contribution, also means that its codebase is publicly accessible, potentially aiding attackers in identifying and exploiting vulnerabilities. However, the discovery and reporting of such flaws by security researchers are also facilitated by its open-source status. The vulnerability was disclosed by the Bifrost project maintainers in a security advisory released on March 15, 2026. The advisory detailed that the exploit involves sending a specially crafted HTTP request to the gateway's management interface. Successful exploitation allows an attacker to gain command-line access to the underlying server hosting the Bifrost gateway. This level of access could enable attackers to steal sensitive information, deploy malware, disrupt services, or use the compromised gateway as a pivot point to attack other systems within the network. The Bifrost project has released version 2.1.0 of its HTTP transport, which includes a patch to address CVE-2026-90898. Users of Bifrost are strongly advised to update to the latest version immediately to mitigate the risk of exploitation. The advisory also noted that while the vulnerability is critical, it requires the attacker to have network access to the Bifrost gateway's management interface. However, in many deployment scenarios, this interface might be exposed to the internet or accessible from less secure network segments, increasing the potential attack surface. The implications of this vulnerability are significant for organizations that rely on Bifrost for managing their LLM integrations. A successful attack could lead to severe data breaches, operational disruptions, and reputational damage. The Bifrost project has not yet released detailed technical information on the exact nature of the command injection, citing security concerns, but confirmed that the fix involves input validation and sanitization of management commands. The security community is closely monitoring the situation, and further analysis of the vulnerability is expected as more information becomes available.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.