Critical Bifrost AI Gateway Vulnerability Allows Unauthenticated Remote Code Execution
A critical remote code execution vulnerability in the Bifrost AI gateway HTTP transport component allows unauthenticated attackers to execute arbitrary commands on the server with a single HTTP request. Tracked as CVE-2026-90898 with a CVSS score of 9.8, the flaw affects all versions before 2.1.0 when management authentication is not properly configured. The open-source gateway routes requests to over 20 LLM providers, making compromised servers a significant risk for broader infrastructure compromise.
