Impact
Bifrost, a gateway service, allows clients to register command‑line “stdio” programs via a management API. When a client is added, Bifrost launches that program immediately, without any MCP handshake. The default configuration has governance.auth_config.is_enabled set to false, meaning the API accepts any request as an administrator. A single unauthenticated POST to /api/mcp/client therefore causes arbitrary code to run as the Bifrost process user (appuser on the official image), providing a direct remote code execution vector backed by a fundamental access‑control weakness (CWE‑284) and lack of authentication (CWE‑306).
Affected Systems
This flaw affects Bifrost HTTP transport releases 1.6.x through 1.6.11 and the transports/v2.0.0 series. The 2.1.0 release and later contain a 403 response for unauthenticated stdio registrations, removing the vulnerability. Users running older versions with default settings are fully vulnerable.
Risk and Exploitability
With a CVSS score of 9.8 the vulnerability is considered critical; the EPSS score is not provided, but the absence of authentication and the existence of administrative functionality make exploitation straightforward. Attackers only need to send an unauthenticated POST request to the management endpoint, which can be done from any network location that can reach the Bifrost instance. The vulnerability is not listed in the CISA KEV catalog, yet its high severity and ease of exploitation warrant immediate attention.
OpenCVE Enrichment