Vulnerability  ·  2026-09-18

mayfly-go AI Assistant — missing authorization on AI assistant API endpoint

VulnerabilityMedium impactGlobalCVE-2026-92992
NVD published this CVSS 6.3 Medium vulnerability on Sept 17, 2026 with a public PoC gist already available.
mayfly-go is a database/ops management tool with an integrated AI assistant; missing authorization on the AI component could let unauthenticated attackers invoke privileged AI-assisted database operations.
An unknown function in server/internal/ai/api/ai.go (AI Assistant component) is missing authorization checks, allowing remote exploitation without valid credentials.
Dromara mayfly-go <= 1.11.5
Track the Dromara project for a patched release; restrict network access to the AI Assistant API endpoint in the interim.
PoC gist
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →