What happened
NVD published this CVSS 6.3 Medium vulnerability on Sept 17, 2026 with a public PoC gist already available.
Why it matters
mayfly-go is a database/ops management tool with an integrated AI assistant; missing authorization on the AI component could let unauthenticated attackers invoke privileged AI-assisted database operations.
Attack vector
An unknown function in server/internal/ai/api/ai.go (AI Assistant component) is missing authorization checks, allowing remote exploitation without valid credentials.
Affected systems
Dromara mayfly-go <= 1.11.5
Mitigation
Track the Dromara project for a patched release; restrict network access to the AI Assistant API endpoint in the interim.