Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html

ONE SENTENCE SUMMARY:

Bifrost AI gateway exposes default-unauthenticated management APIs enabling unauthenticated RCE/SSRF, credential theft, and requiring urgent upgrades and key rotation.

MAIN POINTS:

  1. CVE-2026-90898 enables unauthenticated remote command execution via Bifrost management API.
  2. Issue impacts all HTTP transports versions before 2.1.0 when auth disabled by default.
  3. Attack registers a stdio MCP client using unauthenticated POST to /api/mcp/client.
  4. Bifrost executes the provided command immediately, before MCP handshake, as gateway user.
  5. Successful RCE exposes stored provider API keys and virtual keys on the gateway.
  6. Stock binary binds management API to localhost, reducing remote exposure by default.
  7. Official Docker image binds management API to 0.0.0.0, exposing it when ports published.
  8. transports/v2.1.0 blocks unauthenticated stdio client registration by returning HTTP 403.
  9. CVE-2026-86242 allows unauthenticated HTTP-path plugin download and loading; fixed in v2.0.0.
  10. Multiple recent Bifrost vulnerabilities stem from default-disabled management authentication and echo prior MCP/LiteLLM attack patterns.

TAKEAWAYS:

  1. Upgrade immediately to transports/v2.1.0 to mitigate unauthenticated MCP-stdio RCE.
  2. Enable governance.auth_config.is_enabled and enforce strong management credentials.
  3. Restrict management listener to trusted networks; avoid exposing Docker-published management ports.
  4. Assume compromise if auth was disabled with exposed management API; rotate all keys.
  5. Patch older lines carefully: v2.0.0 fixes plugin issue but not MCP RCE; 1.6.x fixes neither.