Swati Khandelwal 2026年9月22日 人工智能 / 漏洞
开源 AI 网关 Bifrost 存在一个严重漏洞,该网关将请求路由至 20 多家大型语言模型(LLM)提供商。攻击者无需身份验证,只需发出单个 HTTP 请求,即可在网关服务器上运行任意命令。
该漏洞被追踪为 CVE-2026-90898(CVSS 评分:9.8),影响所有管理身份验证已禁用的 Bifrost HTTP transport 版本(即默认配置)。相关修复措施已包含在 transports/v2.1.0 中。
JFrog 安全研究团队的 Yuval Moravchick 发现了该漏洞。他表示,攻击者可以通过向管理 API 端点 /api/mcp/client 发送单个未经身份验证的 POST 请求,注册一个 stdio 类型的 MCP 客户端。Bifrost 会立即以网关进程用户的身份启动指定的命令,且在任何 MCP 握手之前执行。
在官方的 Docker 镜像中,该用户为 appuser。由于网关存储了每个已连接提供商的 API 密钥,在网关进程中执行命令将使攻击者能够访问这些凭据。
默认的 Bifrost 二进制文件将管理 API 绑定到 localhost,这限制了暴露范围仅限于本地机器。而官方 Docker 镜像将其绑定到 0.0.0.0,如果端口已发布,则可从容器外部访问管理 API。
运营商应升级至 transports/v2.1.0,该版本会在未经身份验证的调用者尝试注册 stdio MCP 客户端时返回 403 状态码。无法立即升级的用户应将 governance.auth_config.is_enabled 设置为 true,使用强凭据,并将管理监听器保持在不受信任的网络之外。
JFrog 建议将任何曾以禁用身份验证运行且管理 API 暴露的实例视为已受损,并轮换虚拟密钥和提供商 API 密钥。
运行 transports/v2.0.0 的运营商仍受此 MCP 漏洞影响。该版本仅修复了早期的插件漏洞,并未阻止未经身份验证的注册。1.6.x 系列(直至 1.6.11)均未包含任何修复措施。
同一研究团队的 Or Peles 发现了第二个相关漏洞,并于 9 月 6 日披露。CVE-2026-86242(CVSS 评分:8.1)允许未经身份验证的攻击者注册路径为 HTTP URL 的自定义插件。Bifrost 会下载该文件,将其写入为临时共享对象,并通过 Go 的 plugin.Open 函数加载它。
在需要自定义 Go 插件的动态链接构建中,插件会被加载,其代码以网关进程用户的身份运行。在静态链接构建中(包括官方 Docker 镜像),plugin.Open 会失败,结果仅为服务器端请求伪造(SSRF)。修复措施已包含在 transports/v2.0.0 中。
这两个漏洞的根本原因相同:Bifrost 的管理 API 默认禁用身份验证。这是该项目在不到一个月内披露的第二和第三起安全问题,此前在 8 月下旬修复了一起无关的 SSRF 漏洞(CVE-2026-55245)。
MCP 漏洞遵循了一种已导致现实世界攻击的模式。2026 年 4 月,研究人员披露了 MCP 的 STDIO 传输中存在的设计缺陷,影响了 Anthropic 的官方 SDK。另一款 AI 网关 LiteLLM 中类似的命令注入漏洞在 6 月被积极利用,并被添加到 CISA 已知被利用漏洞目录中。
截至本文发布时,这两起 Bifrost CVE 均未出现在 KEV 目录中。
Swati Khandelwal Sep 22, 2026 Artificial Intelligence / Vulnerability
A critical vulnerability in Bifrost , an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.
The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is disabled, which is the default configuration. A fix is available in transports/v2.1.0.
Yuval Moravchick of JFrog Security Research , who discovered the flaw, said an attacker can register a stdio-type MCP client through a single unauthenticated POST to the management API endpoint /api/mcp/client. Bifrost starts the specified command immediately, before any MCP handshake, as the gateway process user.
On the official Docker image, that user is appuser. Because the gateway stores API keys for every connected provider, executing commands on the gateway process grants the attacker access to those credentials.
The stock Bifrost binary binds the management API to localhost by default, which limits exposure to the local machine. The official Docker image binds to 0.0.0.0, making the management API reachable from outside the container if the port is published.
Operators should upgrade to transports/v2.1.0, which returns 403 when an unauthenticated caller tries to register a stdio MCP client. Those who cannot upgrade immediately should set governance.auth_config.is_enabled to true, use strong credentials, and keep the management listener off untrusted networks.
JFrog advises treating any instance that ran with authentication disabled and the management API exposed as compromised, and rotating virtual keys and provider API keys.
Operators on transports/v2.0.0 are still affected by the MCP flaw. That release fixed only an earlier plugin vulnerability and does not block the unauthenticated registration. The 1.6.x line through 1.6.11 contains neither fix.
A second, related flaw found by Or Peles of the same research team was disclosed on September 6 . CVE-2026-86242 (CVSS score: 8.1) allows an unauthenticated attacker to register a custom plugin whose path is an HTTP URL. Bifrost downloads the file, writes it as a temporary shared object, and loads it through Go's plugin.Open function.
On dynamically linked builds, which Bifrost requires for custom Go plugins, the plugin loads and its code runs as the gateway process user. On statically linked builds, including the official Docker image, plugin.Open fails and the result is server-side request forgery only. The fix is in transports/v2.0.0.
Both flaws share the same root cause: Bifrost's management API ships with authentication disabled by default. They are the second and third security issues disclosed in the project in under a month, after an unrelated SSRF flaw (CVE-2026-55245) fixed in late August.
The MCP flaw follows a pattern that has already led to real-world attacks. In April 2026, researchers disclosed a design flaw in MCP's STDIO transport that affects Anthropic's official SDKs. A similar command-injection flaw in LiteLLM, another AI gateway, was actively exploited and added to CISA's Known Exploited Vulnerabilities catalog in June.
Neither Bifrost CVE appears in the KEV catalog as of publication.
首次收录 · 2026-09-23 · 9.68 分