Critical Bifrost AI Gateway Vulnerability
A critical remote code execution vulnerability has been identified in the Bifrost open-source AI gateway, exposing systems to unauthenticated arbitrary command execution.

A critical vulnerability has been identified in Bifrost, an open-source AI gateway designed to route requests to more than 20 large language model providers. The security issue allows unauthenticated remote code execution, creating a path for attackers to run arbitrary instructions on the host system. To address this threat, developers released an update on September 8, 2026, within transports/v2.1.0, which mitigates the risk by returning a 403 Forbidden response to unauthorized signups.
According to security researcher Yuval Moravchick of the JFrog Security Research Team, who discovered and reported the flaw, the vulnerability affects every release of the Bifrost HTTP transport prior to version 2.1.0 if management authentication is deactivated. Moravchick's findings indicate that an attacker can trigger command execution by sending a single unauthenticated POST request to the management API endpoint. Before any Model Context Protocol handshake can take place, the gateway runs the designated command under the privileges of the gateway process user without verifying credentials.
This security flaw is highly dangerous because it permits the execution of arbitrary instructions without requiring any prior authentication. When running the official Docker image, the gateway process user is configured specifically as "appuser." This restricted environment provides some boundary, but the ability to execute unauthenticated commands remains a severe risk to any system running the outdated gateway software.
While security researchers have highlighted the severity of the flaw, other parties and operators have focused on deployment specifics. It is noted that the stock binary limits exposure by binding to localhost by default, meaning that external exposure depends heavily on deployment configuration, such as using the official Docker image with published ports. No other official statements from third-party vendors or major operators have been released regarding active mitigation strategies beyond applying the official patch.
What remains unknown is how many active production deployments currently run the outdated version of the gateway without management authentication enabled. Additionally, it is currently unknown if this vulnerability has been actively exploited in the wild by malicious actors before the patch was published.
Sources
- The Hacker NewsPage Not Found – The Hacker News
- The Hacker NewsCritical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
- MediumBifrost: The Fastest LLM Gateway for Production-Grade AI Applications
- IONIXCVE-2026-90898 – Unauthenticated RCE via MCP Stdio Client Registration – Bifrost before 2.1.0 - IONIX
- cve.orgCVE Record: CVE-2026-90898
Verified claims
Stills

Written by The Quiet Search. Method: /about.