A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is
Why This Matters
Publisher reporting describes a security event affecting than. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether than is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
CVE: CVE-2026-90898
Affected
AI gatewayBifrostBifrost HTTP transportRemote Code ExecutionAttackers Run CommandsCritical Bifrost AI