Impact
A command‑injection flaw exists in the RunMachineScript function of Dromara Mayfly‑Go. Unsanitized parameters supplied to the machine script functionality are passed directly to the operating system via the CLI execution layer, enabling an attacker to execute arbitrary OS commands. The vulnerability, identified as CWE‑77 and CWE‑78, can compromise confidentiality, integrity and availability of the host. The exploit is remote and requires only the machine:script:run privilege, not an administrative account. A publicly documented exploit demonstrates that the flaw can be exercised by any account with that permission.
Affected Systems
All deployments of Dromara Mayfly‑Go version 1.11.5 and earlier are vulnerable. The affected component is the Machine Script Feature within the core distribution. Any installation that uses server/internal/machine/api/machine_script.go and has machine templates containing {{.param}} placeholders, regardless of the underlying infrastructure, is at risk.
Risk and Exploitability
The CVSS score of 5.3 classifies the vulnerability as moderate impact, while the EPSS score of 1% indicates a relatively low probability of exploitation. However, the publicly listed exploit and absence from the CISA KEV catalog do not mitigate the threat of an attacker leveraging the flaw. The likely attack vector is remote through an API that accepts a machine:script:run call with unsanitized parameters; based on the description, it is inferred that an attacker only needs to possess this permission to trigger the injection, leading to arbitrary command execution on the target host.
OpenCVE Enrichment