Critical Bifrost AI Gateway Flaw Allows Unauthenticated Command Execution
A critical vulnerability in Bifrost, an open-source AI gateway routing requests to over 20 LLM providers, lets an unauthenticated attacker run arbitrary commands on the gateway server with a single HTTP request. Tracked as CVE-2026-90898 (CVSS 9.8), it affects all versions of the Bifrost HTTP transport before 2.1.0.
- CVE-2026-90898 carries a CVSS score of 9.8
- Attack requires a single HTTP request with no credentials
- All Bifrost HTTP transport versions before 2.1.0 are affected
- Bifrost routes requests to more than 20 LLM providers
Read next
Security