PT-2026-91161 · Unknown · Bifrost Transports
CVE-2026-90898
·
Published
2026-09-14
·
Updated
2026-10-05
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Bifrost HTTP transport versions prior to 2.1.0
Description
Bifrost allows the registration of MCP clients through its management API, where a stdio client consists of a command and arguments. The software starts the program in the gateway immediately upon client addition without requiring an MCP handshake. Because the default configuration has
governance.auth config.is enabled set to false, every caller is treated as a local administrator. An unauthenticated POST request to the '/api/mcp/client' endpoint allows an attacker to execute arbitrary commands as the Bifrost process user. This issue can be exploited to expose stored LLM provider API keys and enable lateral movement across AI infrastructure. Real-world incidents have been reported where attackers achieved immediate remote code execution through this flaw.Recommendations
Update Bifrost HTTP transport to version 2.1.0 or later.
Enable management authentication.
Restrict network access to the management interface to trusted IP addresses only.
Exploit
Fix
RCE
Missing Authentication
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Bifrost Transports