OS Command Injection in Dromara Mayfly-go Product
CVE-2026-92993
Key Information:
Badges
What is CVE-2026-92993?
A vulnerability exists in the Dromara Mayfly-go product, specifically within the RunMachineScript function located in server/internal/machine/api/machine_script.go. This vulnerability can be exploited through argument manipulation, resulting in OS command injection. The exploitation of this flaw does not require administrative privileges, allowing any user with the machine:script:run permission and access to certain tags to execute arbitrary commands on affected machines. This includes those using templates with {{.param}} placeholders. The SSH execution layer (Cli.Run) fails to filter input correctly, raising serious security concerns. Despite being contacted regarding this issue, the vendor has not provided any input.
Affected Version(s)
mayfly-go 1.11.0
mayfly-go 1.11.1
mayfly-go 1.11.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
