CVE Tools
Back to feed
PoC public Bifrost AI Gateway ai-ml Bifrost rce

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

The Hacker News·By The Hacker News··2 min read
CVE Tools coverage

JFrog researchers released proof-of-concept details for CVE-2026-90898, a CVSS 9.8 flaw in Bifrost AI Gateway that lets unauthenticated attackers launch commands through MCP client registration when management authentication is disabled. All Bifrost HTTP transport versions before 2.1.0 are affected; operators should update to transports/v2.1.0 and rotate provider credentials if an exposed instance ran without authentication. The research also covers CVE-2026-86242, fixed in transports/v2.0.0, which can enable code execution on dynamically linked builds or SSRF on statically linked builds.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store