PT-2026-95071 · Dromara+1 · Mayfly-Go
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Dromara mayfly-go versions prior to 1.11.6
Description
A missing authorization issue exists within the AI Assistant component, specifically in the
server/internal/ai/api/ai.go file. This flaw allows for remote exploitation via a whitelist bypass that is one-token wide. Consequently, compound commands containing curl, wget, or sed can be executed automatically without required approval, as the system grants self-approval to the session user.Recommendations
Apply the patch identified by 74bcb926eb4f5f94e7681144d7bf2168a0ec7cde for versions prior to 1.11.6.
Exploit
Fix
Missing Authorization
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mayfly-Go