00:00
2026-09-14
research.jfrog.com
ai-safety
Bifrost is vulnerable to Unauthenticated Remote Code Execution via MCP Stdio Client Registration
Bifrost HTTP transport versions before 2.1.0 allow unauthenticated remote code execution through MCP stdio client registration, according to a vulnerability disclosure from the Bifrost project. With t…