Bifrost AI 게이트웨인에서 인증 없이 명령을 실행할 수 있는 심각한 취약점 발견.
Bifrost라는 오픈소스 AI 게이트웨이에서 발견된 취약점은 인증되지 않은 공격자가 단일 HTTP 요청으로 서버에서 임의의 명령을 실행할 수 있게 합니다. 이 취약점은 CVE-2026-90898로 추적되며 CVSS 점수는 9.8로 매우 높습니다. 관리 인증이 이루어지지 않는 모든 Bifrost HTTP 전송 버전 2.1.0 이전에 영향을 미칩니다.
A critical vulnerability in Bifrost AI gateway allows unauthenticated command execution.
A vulnerability in Bifrost, an open-source AI gateway, allows unauthorized attackers to execute arbitrary commands on the gateway server with a single HTTP request. Tracked as CVE-2026-90898, it has a high CVSS score of 9.8. This flaw affects all versions of the Bifrost HTTP transport prior to 2.1.0 when management authentication is not implemented.