SeguridadNo verificado

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is

Se muestra el contenido original; la traduccion localizada aun no esta disponible.

Qué ocurrió

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is

Por que importa

The incident may affect operational continuity, asset safety or trust around Security. Watch for verified scope and remediation.

Entidades afectadas

Ver evidencia

1 articulos · 1 informe original · 1 independientes

  1. The Hacker NewsFuente primaria · Respalda · EN · 100%
    Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

Afirmaciones

  • Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials Observado

Conflictos

No se detectaron conflictos importantes en la evidencia disponible.

Cronología

  1. Primera publicación

Movimiento del mercado posterior al evento

La reacción del mercado aún no está disponible para este activo y periodo.

Explicación de puntuaciones

Confianza · fórmula confidence-2.1.0
Fiabilidad de fuentes80
Corroboración independiente51
Evidencia primaria35
Coherencia de afirmaciones82
Confianza de extracción82
Calidad de atribución90
Impacto · fórmula impact-2.1.0
Magnitud del evento100
Relevancia de mercado74
Importancia de entidades42
Alcance del mercado45
Novedad68
Urgencia100
Clasificación · fórmula rank-1.0.0
Factor de confianza0.8425
Factor de actualidad0.9878
Bono de urgencia8
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials | IntelCap