Description
A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of the argument params results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Exploitation needs no admin account. Any account holding machine:script:run plus tag access reaches arbitrary command execution on machines whose templates contain {{.param}} placeholders; the SSH exec layer (Cli.Run) also applies no input filtering to any caller. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-17
Score: 5.3 Medium
EPSS: 1.5% Low
KEV: No
Impact: Arbitrary Remote Command Execution
Action: Patch Immediately
AI Analysis

Impact

A command‑injection flaw exists in the RunMachineScript function of Dromara Mayfly‑Go. Unsanitized parameters supplied to the machine script functionality are passed directly to the operating system via the CLI execution layer, enabling an attacker to execute arbitrary OS commands. The vulnerability, identified as CWE‑77 and CWE‑78, can compromise confidentiality, integrity and availability of the host. The exploit is remote and requires only the machine:script:run privilege, not an administrative account. A publicly documented exploit demonstrates that the flaw can be exercised by any account with that permission.

Affected Systems

All deployments of Dromara Mayfly‑Go version 1.11.5 and earlier are vulnerable. The affected component is the Machine Script Feature within the core distribution. Any installation that uses server/internal/machine/api/machine_script.go and has machine templates containing {{.param}} placeholders, regardless of the underlying infrastructure, is at risk.

Risk and Exploitability

The CVSS score of 5.3 classifies the vulnerability as moderate impact, while the EPSS score of 1% indicates a relatively low probability of exploitation. However, the publicly listed exploit and absence from the CISA KEV catalog do not mitigate the threat of an attacker leveraging the flaw. The likely attack vector is remote through an API that accepts a machine:script:run call with unsanitized parameters; based on the description, it is inferred that an attacker only needs to possess this permission to trigger the injection, leading to arbitrary command execution on the target host.

Generated by OpenCVE AI on September 26, 2026 at 05:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Dromara Mayfly‑Go to a release that includes the command‑injection fix, or apply the vendor’s patch if available.
  • Restrict the machine:script:run permission to trusted or administrative accounts to reduce the attack surface.
  • Remove or sanitize {{.param}} placeholders from machine templates, or enforce input validation before executing the command.

Generated by OpenCVE AI on September 26, 2026 at 05:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of the argument params results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Exploitation needs no admin account. Any account holding machine:script:run plus tag access reaches arbitrary command execution on machines whose templates contain {{.param}} placeholders; the SSH exec layer (Cli.Run) also applies no input filtering to any caller. The vendor was contacted early about this disclosure but did not respond in any way.
Title Dromara mayfly-go Machine Script Feature machine_script.go RunMachineScript os command injection
First Time appeared Dromara
Dromara mayfly-go
Weaknesses CWE-77
CWE-78
CPEs cpe:2.3:a:dromara:mayfly-go:*:*:*:*:*:*:*:*
Vendors & Products Dromara
Dromara mayfly-go
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Dromara Mayfly-go
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T15:44:54.001Z

Reserved: 2026-09-17T14:06:13.952Z

Link: CVE-2026-92993

cve-icon Vulnrichment

Updated: 2026-09-22T15:30:28.954Z

cve-icon NVD

Status : Deferred

Published: 2026-09-17T20:19:00.233

Modified: 2026-09-22T16:18:12.870

Link: CVE-2026-92993

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-26T05:45:05Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')