08:01
2026-09-26
dev.to
ai-agents
Your MCP Server Is Listening on 0.0.0.0 and Accepting Anonymous Client Registrations
JFrog Security Research disclosed CVE-2026-90898, a CVSS 9.8 flaw in the open-source Bifrost AI gateway that lets an unauthenticated attacker achieve remote command execution by POSTing a stdio-type M…