Junglewise Threat Intelligence

CVE-2026-92993: Dromara mayfly-go OS command injection in machine script

CVE-2026-92993 · Severity: medium · CVSS 6.3 · Published 2026-09-17

Vendors: Dromara.

Executive brief

mayfly-go is a browser-based management platform for servers, databases, and infrastructure. An attacker with limited script-execution permissions can inject arbitrary operating system commands through template parameters, gaining complete command execution on managed machines. This allows unauthorized access to systems and data that the attacker should not be able to reach.

Technical details

The vulnerability is an OS command injection (CWE-78) in the RunMachineScript function (server/internal/machine/api/machine_script.go). User-supplied parameters are substituted directly into Go text/template shells without sanitization and then executed over SSH. An attacker with machine:script:run permission and tag access can craft malicious parameter values containing shell metacharacters to break out of the template context and execute arbitrary commands. The SSH execution layer (Cli.Run) applies no input filtering. No authentication bypass is required beyond basic account access; exploitation is remote and a public proof-of-concept is available.

Affected products

  • Dromara mayfly-go up to 1.11.5

Timeline

  • 2026-09-17: disclosed: CVE-2026-92993 published
  • 2026-08-21: other: Vendor contacted privately; no response

References

Related threats