Arbitrary Code Injection Affecting github.com/maximhq/bifrost/transports/bifrost-http/server package, versions <2.0.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.06% (64th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMMAXIMHQBIFROSTTRANSPORTSBIFROSTHTTPSERVER-19784340
  • published14 Sept 2026
  • disclosed6 Sept 2026
  • creditOr Peles

Introduced: 6 Sep 2026

NewCVE-2026-86242  (opens in a new tab)
CWE-94  (opens in a new tab)

How to fix?

A fix was pushed into the master branch but not yet published.

Overview

Affected versions of this package are vulnerable to Arbitrary Code Injection through the createPlugin and updatePlugin handlers. An attacker can load arbitrary native code into the gateway process by sending POST /api/plugins or PUT /api/plugins/{name} with a non-builtin path when dashboard authentication is disabled or unconfigured. Because the plugin path is treated as a shared object and dlopen()'d in-process, a successful request lets the attacker execute code as the Bifrost process user. For affected deployments that leave management authentication off, this turns a reachable admin endpoint into remote code execution and can compromise the gateway host.

Workarounds

  • Enable dashboard/admin authentication before creating or updating custom plugins with a non-builtin path through /api/plugins or /api/plugins/{name}; this prevents unauthenticated callers from setting a plugin path that would be loaded as native code in the gateway process.
  • If you host custom plugin .so files on an internal/private-network URL, add that host to server.plugin_download_private_allowlist; this prevents the plugin downloader from blocking your trusted artifact source while still limiting exposure to SSRF against internal or metadata endpoints.

CVSS Base Scores

version 4.0
version 3.1