Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
PoC publicBifrost AI GatewayOur summary
JFrog researchers released proof-of-concept details for CVE-2026-90898, a CVSS 9.8 flaw in Bifrost AI Gateway that lets unauthenticated attackers launch commands through MCP client registration when management authentication is disabled. All Bifrost HTTP transport versions before 2.1.0 are affected; operators should update to transports/v2.1.0 and rotate provider credentials if an exposed instance ran without authentication. The research also covers CVE-2026-86242, fixed in transports/v2.0.0, which can enable code execution on dynamically linked builds or SSRF on statically linked builds.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.