PT-2026-95071 · Dromara+1 · Mayfly-Go

·

CVE-2026-92992

·

Published

2026-09-17

·

Updated

2026-09-17

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Dromara mayfly-go versions prior to 1.11.6
Description A missing authorization issue exists within the AI Assistant component, specifically in the server/internal/ai/api/ai.go file. This flaw allows for remote exploitation via a whitelist bypass that is one-token wide. Consequently, compound commands containing curl, wget, or sed can be executed automatically without required approval, as the system grants self-approval to the session user.
Recommendations Apply the patch identified by 74bcb926eb4f5f94e7681144d7bf2168a0ec7cde for versions prior to 1.11.6.

Exploit

Fix

Missing Authorization

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92992

Affected Products

Mayfly-Go