important · Remote code execution
An unauthenticated Bifrost management API can load attacker-supplied native code under narrow build conditions.
Affects
Bifrost HTTP transport, an open-source gateway for routing requests among AI-model providers, on dynamically linked Linux builds.
With dashboard authentication disabled or unconfigured, a caller can register a custom plugin URL that a dynamically linked, plugin-capable build downloads and passes to Go's plugin loader.
Detail and 4 sources
JFrog demonstrated the chain with a canary shared object whose Init function ran in the Bifrost process.
Sources
ResearchBifrost is vulnerable to Unauthenticated Remote Code Execution via a Custom Plugin HTTP Path on Dynamically Linked Builds | JFSA-2026-001684572 - JFrog Security ResearchResearchBifrost HTTP 플러그인 코드 실행(CVE-2026-86242)|영향 조건과 대응 | 시큐포커스 NOWCode / PoCpath normalization auth bypass by akshaydeo · Pull Request #5763 · maximhq/bifrost · GitHubCode / PoCRelease Bifrost HTTP v2.0.0 · maximhq/bifrost · GitHub