Bifrost, an open-source AI gateway that routes requests to more than 20 large language model providers, has a critical vulnerability that requires no authentication to exploit. Tracked as CVE-2026-90898, the flaw can be triggered with a single HTTP request, allowing an attacker to run arbitrary commands on the gateway server.

The gateway's role as a central routing point makes this particularly concerning. A compromised gateway could give an attacker a foothold in the underlying infrastructure, and because Bifrost handles traffic to many LLM providers, the potential blast radius is wide. The source report does not include additional technical details or a patched version, so administrators are advised to watch for updates and assess their exposure.

This article is based on a single source, so there are no differing accounts to compare. The main takeaway is that an unauthenticated remote command execution flaw in a widely used AI gateway is a serious security risk.