Dromara · Mayfly-Go · CVE-2026-92992
**Name of the Vulnerable Software and Affected Versions**
Dromara mayfly-go versions prior to 1.11.6
**Description**
A missing authorization issue exists within the AI Assistant component, specifically in the `server/internal/ai/api/ai.go` file. This flaw allows for remote exploitation via a whitelist bypass that is one-token wide. Consequently, compound commands containing `curl`, `wget`, or `sed` can be executed automatically without required approval, as the system grants self-approval to the session user.
**Recommendations**
Apply the patch identified by 74bcb926eb4f5f94e7681144d7bf2168a0ec7cde for versions prior to 1.11.6.