{"api_version":"v1","generated_at":"2026-10-09T04:30:00+00:00","product":{"cve_count":2,"evidence_gap_note":"Official registry publication history is linked, but a publisher support or retirement boundary has not been established.","id":"security:cve-maximhq-bifrost-60218bc9b621","lifecycle_state":"evidence_gap","linked_lifecycle_url":"https://lifecycle.blacktree.nl/libraries/npm/bifrost","name":"Bifrost","next_cursor":null,"observations":[{"affected":"Bifrost: < 2.1.0","affected_versions_present":true,"cve_id":"CVE-2026-90898","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-90898","fixed":"Upgrade Bifrost HTTP transport to 2.1.0 or later. PR #6757 returns 403 for unauthenticated stdio MCP client registration when dashboard authentication is disabled or unconfigured. Authenticated admins can still add stdio clients. The 1.6.x line through 1.6.11 and transports/v2.0.0 do not include this change.","last_modified":"2026-09-14T11:19:46.276Z","patch_url":"https://github.com/maximhq/bifrost/pull/6757","primary_source":"","published":"2026-09-14T10:18:53.454Z"},{"affected":"< 2.0.0","affected_versions_present":true,"cve_id":"CVE-2026-86242","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-86242","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-09-08T18:23:28.573Z","patch_url":"","primary_source":"","published":"2026-09-06T11:20:11.759Z"},{"affected":"< 1.5.17","affected_versions_present":true,"cve_id":"CVE-2026-55245","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-55245","fixed":"1.5.17.","last_modified":"2026-08-28T19:54:10.966Z","patch_url":"https://github.com/maximhq/bifrost/security/advisories/GHSA-w98g-5w9p-p3rc","primary_source":"","published":"2026-08-28T18:24:16.723Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"maximhq"}}
