Impact
The vulnerability lies in the AI Assistant component of Dromara mayfly‑go, specifically an undocumented function inside file server/internal/ai/api/ai.go. An attacker can manipulate input to bypass the authorization checks, allowing the execution of arbitrary compound commands that include curl, wget or sed. This results in a missing authorization flaw, permitting remote command execution without user approval.
Affected Systems
Affected versions are all releases of Dromara mayfly‑go up to 1.11.5 inclusive. The fix is provided in commit 74bcb926eb4f5f94e7681144d7bf2168a0ec7cde and should be applied by upgrading to the patched version or backporting the commit.
Risk and Exploitability
Based on the description, it is inferred that the attacker sends a crafted request to the AI Assistant endpoint over HTTP, a remote action that triggers the missing authorization flaw. The CVSS base score of 5.3 indicates a moderate impact, while the EPSS score of less than 1% signals a low likelihood of exploitation at this time. The vulnerability is not listed in CISA KEV. Successful exploitation would allow the attacker to run arbitrary shell commands and potentially compromise the host.
OpenCVE Enrichment