Source: The Hacker News
Author: info@thehackernews.com (The Hacker News)
URL: https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html
ONE SENTENCE SUMMARY:
Bifrost AI gateway exposes default-unauthenticated management APIs enabling unauthenticated RCE/SSRF, credential theft, and requiring urgent upgrades and key rotation.
MAIN POINTS:
- CVE-2026-90898 enables unauthenticated remote command execution via Bifrost management API.
- Issue impacts all HTTP transports versions before 2.1.0 when auth disabled by default.
- Attack registers a stdio MCP client using unauthenticated POST to /api/mcp/client.
- Bifrost executes the provided command immediately, before MCP handshake, as gateway user.
- Successful RCE exposes stored provider API keys and virtual keys on the gateway.
- Stock binary binds management API to localhost, reducing remote exposure by default.
- Official Docker image binds management API to 0.0.0.0, exposing it when ports published.
- transports/v2.1.0 blocks unauthenticated stdio client registration by returning HTTP 403.
- CVE-2026-86242 allows unauthenticated HTTP-path plugin download and loading; fixed in v2.0.0.
- Multiple recent Bifrost vulnerabilities stem from default-disabled management authentication and echo prior MCP/LiteLLM attack patterns.
TAKEAWAYS:
- Upgrade immediately to transports/v2.1.0 to mitigate unauthenticated MCP-stdio RCE.
- Enable governance.auth_config.is_enabled and enforce strong management credentials.
- Restrict management listener to trusted networks; avoid exposing Docker-published management ports.
- Assume compromise if auth was disabled with exposed management API; rotate all keys.
- Patch older lines carefully: v2.0.0 fixes plugin issue but not MCP RCE; 1.6.x fixes neither.