criticalresolved

Bifrost MCP management API command execution (CVE-2026-90898)

Bifrost's management API started an attacker-supplied command as soon as an MCP stdio client was registered, before any MCP handshake. Management authentication is off by default, so a reachable endpoint meant unauthenticated command execution. CVSS 9.8, fixed in HTTP transport 2.1.0.

The management API accepts an MCP stdio client definition that contains a command and its arguments. In releases before HTTP transport 2.1.0, Bifrost launched that program the moment the client was registered, before any MCP handshake took place.

With governance.auth_config.is_enabled left false, the documented default, one unauthenticated POST to /api/mcp/client ran a command as the Bifrost process user. The stock binary binds to localhost and the official Docker image binds to 0.0.0.0, so exposure depends on how the port is published. No exploitation in the wild has been reported.

Takeaway

An AI gateway's management API holds provider keys and MCP configuration, which makes it a production control plane. Turn its authentication on and keep it off the network paths that carry model traffic.

Sources

mcpbifrostai-gatewaycommand-executionCVE-2026-90898