CVE-2026-92992 | Dromara mayfly-go up to 1.11.5 AI Assistant ai.go authorization

SecurityVulns

A vulnerability marked as critical has been reported in Dromara mayfly-go up to 1.11.5. The affected element is an unknown function of the file server/internal/ai/api/ai.go of the component AI Assistant. The manipulation leads to missing authorization.

This vulnerability is referenced as CVE-2026-92992. Remote exploitation of the attack is possible. Furthermore, an exploit is available.

Applying a patch is the recommended action to fix this issue.

The whitelist bypass is one-token wide. Any compound command containing curl, wget or sed auto-runs without approval; approval is granted by the same session user (self-approval). This issue got fixed with a silent patch.VulDB Recent EntriesRead More