Executive brief
Dromara mayfly-go is a browser-based management platform for Linux servers, databases, and infrastructure components. An authentication bypass in the AI Assistant component allows authenticated users without proper permissions to execute arbitrary commands on unauthorized machines and access restricted databases, bypassing the authorization checks that normally protect sensitive resources.
Technical details
The vulnerability is a missing resource-level authorization flaw (CWE-862) in the AI Assistant's WebSocket endpoint (/api/ai/chat) affecting versions 1.11.0 through 1.11.5. The AI chat component fails to perform CanAccess checks before resolving and executing actions on machines and databases—a control that is consistently implemented in regular APIs. Attackers can supply arbitrary credential or database identifiers, and a command whitelist bypass allows unauthorized commands to execute if any token matches (e.g., "hostname; touch /tmp/x" bypasses approval). The approval flow is self-executed by the same session user, providing no additional authorization gate. Additionally, an OS command injection vulnerability (CWE-78) in machine-script template parameters allows authenticated users with only machine:script:run permission to inject shell commands. The patch (commit 74bcb926eb4f5f94e7681144d7bf2168a0ec7cde) was applied silently.
Affected products
- Dromara mayfly-go 1.11.0 to 1.11.5
Timeline
- 2026-08-21: disclosed: Vulnerability reported to vendor; PR #129 requesting private vulnerability reporting left unanswered for ~4 months
- 2026-09-17: disclosed: Public disclosure via NVD
- 2026-09-17: patched: Silent patch applied (commit 74bcb926eb4f5f94e7681144d7bf2168a0ec7cde)