chiprook
← Security
SecuritySeptember 22, 2026, 23:41

Critical Bifrost AI Gateway Flaw Allows Unauthenticated Command Execution

A critical vulnerability in Bifrost, an open-source AI gateway routing requests to over 20 LLM providers, lets an unauthenticated attacker run arbitrary commands on the gateway server with a single HTTP request. Tracked as CVE-2026-90898 (CVSS 9.8), it affects all versions of the Bifrost HTTP transport before 2.1.0.

Critical Bifrost AI Gateway Flaw Allows Unauthenticated Command Execution
#Bifrost
Read next
Security

Florida Revokes Flock Camera Permits as ALPR Vandalism Hits 36 States

Security

Shai-Hulud attack steals 170 private CrowdSec repositories

Security

Western Australia Police report 900K facial scans in 3-month LFR trial

Security

Check Point warns of Management Server zero-day exploited in attacks