CVE-2026-86242 | maximhq Bifrost up to 1.x HTTP Transport /api/plugins plugin.Open server-side request forgery
A vulnerability described as critical has been identified in maximhq Bifrost up to 1.x. Impacted is the function plugin.Open of the file /api/plugins of the component HTTP Transport. Such manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-86242. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.