{"data":{"id":"6e75ecf6-6247-457a-b18d-b8409eb3874f","title":"Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials","summary":"A critical vulnerability in Bifrost, an open-source AI gateway (software that routes requests to multiple language models), allows attackers to run arbitrary commands (any code they want) on the server without needing credentials when management authentication is disabled by default. The flaw is especially dangerous because the gateway stores API keys for connected providers, so compromised servers give attackers access to those credentials, and the official Docker image exposes the vulnerable management API to outside networks.","solution":"Operators should upgrade to transports/v2.1.0, which blocks unauthenticated registration. For those unable to upgrade immediately, the source recommends enabling authentication by setting governance.auth_config.is_enabled to true, using strong credentials, and keeping the management listener off untrusted networks. Additionally, any instance that ran with authentication disabled and exposed management API should be treated as compromised, and virtual keys and provider API keys should be rotated.","labels":["security"],"sourceUrl":"https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html","publishedAt":"2026-09-22T16:41:12.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"critical","attackType":["supply_chain"],"issueType":"news","affectedPackages":null,"affectedVendors":[],"affectedVendorsRaw":["Bifrost","Anthropic","LiteLLM"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-22T16:41:12.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"api","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}