ALEXKRI.NET
Resume Contact
← Back

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

An AI gateway holds the API keys for every provider behind it, which makes it the most rewarding single box in the stack to own. CVE-2026-90898 (CVSS 9.8) let an unauthenticated POST to /api/mcp/client register a stdio MCP client, and Bifrost would launch the command before any handshake ever happened. Management auth was off by default. Fixed in transports/v2.1.0 - and worth auditing what else you run with auth optional.

Read the source ↗