Critical Vulnerability in Bifrost AI Gateway Enables Full Server Compromise with a Single HTTP Request

A critical flaw in the open-source Bifrost AI gateway enables remote code execution without credentials. Attackers can compromise the server with a single HTTP request. Tracked as CVE-2026-90898 and carrying a maximum CVSS score of 9.8, the vulnerability poses an urgent risk to any organization using the tool to manage access to large language models (LLMs).

The flaw affects the gateway's HTTP transport component in all versions prior to 2.1.0. Exploitation is trivial, requiring only a single crafted HTTP request and no prior authentication. The attack is particularly insidious because it leverages a common operational configuration: management authentication being disabled. While this setting is often used for convenience in development or internal environments, it directly enables this attack vector.

A compromised Bifrost instance is a high-value prize. The gateway serves as a central junction, routing requests to over 20 different LLM providers. An attacker with full control could exfiltrate sensitive data, manipulate AI model outputs, or use the server as a pivot point to attack the broader network.

Immediate Action Required: Patch and Harden

Affected teams must act urgently. The developer-recommended remediation is a two-step process:

  1. Harden: As an immediate interim measure, enable management authentication on all Bifrost deployments. Additionally, apply strict network controls (e.g., firewall rules) to ensure the management interface is only accessible from trusted internal networks.
  2. Upgrade: Upgrade all Bifrost installations to version 2.1.0 or later, which contains the permanent fix for CVE-2026-90898.
AI Toolchains Demand Rigorous Security Scrutiny

This incident is a stark reminder that open-source tools supporting the AI pipeline—from gateways to orchestrators—have become critical infrastructure. Their central role in handling sensitive workloads and data makes them prime targets for attackers.

The Bifrost vulnerability underscores the danger of configuration drift, where settings safe in development are pushed into production without security review. As AI stacks grow in complexity, organizations must apply the same security rigor to these tools as they do to core applications, emphasizing secure-by-default principles and proactive dependency management.


Bifrost AI網關存在嚴重漏洞,單一HTTP請求即可完全入侵伺服器

開源Bifrost AI網關存在嚴重漏洞,允許未經認證的攻擊者執行遠端代碼。攻擊者可透過單一HTTP請求入侵伺服器。該漏洞編號為CVE-2026-90898,CVSS評分為最高級別的9.8分,對任何使用該工具管理大型語言模型(LLM)存取權限的機構構成緊急風險。

此漏洞影響2.1.0之前所有版本網關的HTTP傳輸元件。利用方式十分簡單,攻擊者只需發送單一特製HTTP請求,無需事先認證。攻擊手段尤其惡劣,因其利用了常見的營運配置:管理認證功能被停用。雖然此設定在開發或內部環境中常因便利性而啟用,但卻直接開啟了此攻擊途徑。

被入侵的Bifrost實例具有極高價值。該網關作為中樞節點,將請求路由至超過20家不同的LLM服務商。完全控制此網關的攻擊者可竊取敏感資料、操縱AI模型輸出,或利用該伺服器作為跳板攻擊更廣泛的網絡。

須立即採取行動:修補漏洞並加強防護

受影響團隊必須緊急行動。開發者建議的補救措施分為兩個步驟:

  1. 加強防護: 作為即時過渡措施,請在所有Bifrost部署中啟用管理認證。同時,應用嚴格的網絡控制措施(例如防火牆規則),確保管理界面僅可從受信任的內部網絡訪問。
  2. 升級版本: 將所有Bifrost安裝升級至2.1.0或更高版本,該版本包含針對CVE-2026-90898的永久修復。
AI工具鏈需接受嚴格安全審查

此次事件明確提醒,支援AI流程的開源工具——從網關到協調器——已成為關鍵基礎設施。它們在處理敏感工作負載與資料方面的核心角色,使其成為攻擊者的首要目標。

Bifrost漏洞凸顯了「設定漂移」的危險:開發環境中安全的設定可能未經安全審查便被部署至生產環境。隨著AI架構日益複雜,機構必須對這些工具應用與核心應用同等嚴格的安全標準,強調預設安全原則與主動式的依賴管理。

新聞來源 / Original News Source