Back to all news
Security

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

The Hacker News·September 22, 2026·1 min read
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

A critical vulnerability in Bifrost, an open-source AI gateway routing requests to over 20 LLM providers, allows unauthenticated attackers to execute arbitrary commands on the gateway server via a single HTTP request. Tracked as CVE-2026-90898 with a CVSS score of 9.8, it affects all versions before 2.1.0 when management authentication is enabled.

Read at The Hacker News
Daily crypto arcade

Read the news, then play it.

Chainshorts turns crypto headlines into a daily game. Catch up in 60 words, then jump into daily lucky draws for a shot at the pot.

Open ChainshortsGet it on the Solana dApp Store