Maximhq Bifrost vulnerabilities
3 known vulnerabilities affecting maximhq/bifrost.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2
Vulnerabilities
Page 1 of 1
CVE-2026-86242P2HIGHCVSS 8.1PoCfixed in 2.0.02026-09-06
CVE-2026-86242 [HIGH] CWE-94 CVE-2026-86242: Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL throu
Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The shared-object loader treats an http-prefixed path as a download URL, writes the body to a temporary .so, and passe
nvd
CVE-2026-90898P2CRITICALCVSS 9.8fixed in 2.1.02026-09-14
CVE-2026-90898 [CRITICAL] CWE-284 CVE-2026-90898: Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bif
Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required.
The default is governance.auth_config.is_enabled=false. Auth off means every caller is a local admin. One unauthenticated POST /api/mcp/client is en
nvd
CVE-2026-55245P3HIGHCVSS 8.7fixed in 1.5.172026-08-28
CVE-2026-55245 [HIGH] CWE-918 CVE-2026-55245: Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the is
Bifrost is an enterprise AI gateway for routing requests to model providers. Prior to 1.5.17, the isPublicIP function in core/providers/utils/fetch.go, reached through FetchAndEncodeURL for Bedrock and Vertex image or document URLs, classifies Carrier-Grade NAT 100.64.0.0/10, IPv6 6to4 2002::/16, NAT64 64:ff9b::/96 and 64:ff9b:1::/48, and deprecated I
nvd