Dromara Mayfly Go
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Dromara Mayfly Go.
By the Year
In 2026 there have been 2 vulnerabilities in Dromara Mayfly Go with an average score of 5.3 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 2 | 5.30 |
It may take a day or so for new Mayfly Go vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Dromara Mayfly Go Security Vulnerabilities
Dromara mayfly-go 1.11.5 Remote OS Command Injection via Machine Script
CVE-2026-92993
5.3 - Medium
- September 17, 2026
A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of the argument params results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Exploitation needs no admin account. Any account holding machine:script:run plus tag access reaches arbitrary command execution on machines whose templates contain {{.param}} placeholders; the SSH exec layer (Cli.Run) also applies no input filtering to any caller. The vendor was contacted early about this disclosure but did not respond in any way.
Shell injection
Dromara mayfly-go 1.11.5 AI Auth bypass
CVE-2026-92992
5.3 - Medium
- September 17, 2026
A security vulnerability has been detected in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The identifier of the patch is 74bcb926eb4f5f94e7681144d7bf2168a0ec7cde. Applying a patch is the recommended action to fix this issue. The whitelist bypass is one-token wide. Any compound command containing curl, wget or sed auto-runs without approval; approval is granted by the same session user (self-approval). This issue got fixed with a silent patch.
AuthZ
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Dromara Mayfly Go or by Dromara? Click the Watch button to subscribe.