---
id: CVE-2026-92993
title: A vulnerability was detected in Dromara mayfly-go up to 1.11.5
summary: >-
  A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted
  element is the function RunMachineScript of the file
  server/internal/machine/api/machine_script.go of the component Machine Script
  Feature. The manipulation of …
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-77
  - CWE-78
vendor: Dromara
product: mayfly-go
affected:
  - mayfly-go 1.11.0
  - mayfly-go 1.11.1
  - mayfly-go 1.11.2
  - mayfly-go 1.11.3
  - mayfly-go 1.11.4
  - mayfly-go 1.11.5
published: '2026-09-17'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T16:18:12.870'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92993'
references:
  - url: 'https://gist.github.com/xufengnian/b95662ba0d8881cfc5ba0bb99cbfc086'
    label: cna@vuldb.com
  - url: 'https://github.com/dromara/mayfly-go/'
    label: cna@vuldb.com
  - url: 'https://github.com/dromara/mayfly-go/pull/129'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-92993'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/942254'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/406447'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/406447/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
epss: 0.01458
epssPercentile: 0.7242
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T15:30:27.970601Z'
ingestedAt: '2026-09-17T19:26:25.321Z'
---

## Overview

A vulnerability was detected in Dromara mayfly-go up to 1.11.5. The impacted element is the function RunMachineScript of the file server/internal/machine/api/machine_script.go of the component Machine Script Feature. The manipulation of the argument params results in os command injection. The attack can be executed remotely. The exploit is now public and may be used. Exploitation needs no admin account. Any account holding machine:script:run plus tag access reaches arbitrary command execution on machines whose templates contain {{.param}} placeholders; the SSH exec layer (Cli.Run) also applies no input filtering to any caller. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
