Description
A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The identifier of the patch is 74bcb926eb4f5f94e7681144d7bf2168a0ec7cde. Applying a patch is the recommended action to fix this issue. The whitelist bypass is one-token wide. Any compound command containing curl, wget or sed auto-runs without approval; approval is granted by the same session user (self-approval). This issue got fixed with a silent patch.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized Command Execution
Action: Patch
AI Analysis

Impact

The vulnerability lies in the AI Assistant component of Dromara mayfly‑go, specifically an undocumented function inside file server/internal/ai/api/ai.go. An attacker can manipulate input to bypass the authorization checks, allowing the execution of arbitrary compound commands that include curl, wget or sed. This results in a missing authorization flaw, permitting remote command execution without user approval.

Affected Systems

Affected versions are all releases of Dromara mayfly‑go up to 1.11.5 inclusive. The fix is provided in commit 74bcb926eb4f5f94e7681144d7bf2168a0ec7cde and should be applied by upgrading to the patched version or backporting the commit.

Risk and Exploitability

Based on the description, it is inferred that the attacker sends a crafted request to the AI Assistant endpoint over HTTP, a remote action that triggers the missing authorization flaw. The CVSS base score of 5.3 indicates a moderate impact, while the EPSS score of less than 1% signals a low likelihood of exploitation at this time. The vulnerability is not listed in CISA KEV. Successful exploitation would allow the attacker to run arbitrary shell commands and potentially compromise the host.

Generated by OpenCVE AI on September 19, 2026 at 00:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the official patch corresponding to commit 74bcb926eb4f5f94e7681144d7bf2168a0ec7cde by upgrading to the patched release of mayfly‑go.
  • If a patch cannot be applied immediately, restrict or disable the AI Assistant API endpoint to prevent unauthenticated command execution.
  • As a temporary workaround, modify the whitelist configuration so that a single-token bypass is no longer permitted, requiring multiple tokens or disabling auto‑run behavior for compound commands.

Generated by OpenCVE AI on September 19, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The identifier of the patch is 74bcb926eb4f5f94e7681144d7bf2168a0ec7cde. Applying a patch is the recommended action to fix this issue. The whitelist bypass is one-token wide. Any compound command containing curl, wget or sed auto-runs without approval; approval is granted by the same session user (self-approval). This issue got fixed with a silent patch.
Title Dromara mayfly-go AI Assistant ai.go authorization
First Time appeared Dromara
Dromara mayfly-go
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:dromara:mayfly-go:*:*:*:*:*:*:*:*
Vendors & Products Dromara
Dromara mayfly-go
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Dromara Mayfly-go
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-17T19:09:08.362Z

Reserved: 2026-09-17T14:05:58.251Z

Link: CVE-2026-92992

cve-icon Vulnrichment

Updated: 2026-09-17T19:09:02.444Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T19:17:07.430

Modified: 2026-09-17T21:12:30.593

Link: CVE-2026-92992

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:30:16Z

Weaknesses