Aiyiyi121 · Sxdevops · CVE-2026-93967
**Name of the Vulnerable Software and Affected Versions**
aiyiyi121 SxDevOps versions 1.0 through 1.1
**Description**
A command injection issue exists within the Command Handler component. The `generate host task()` function in the `backend/aiops/services.py` file fails to properly handle the `command` argument, allowing remote attackers to execute arbitrary commands.
**Recommendations**
Apply patch 2b4bf8585c3e731e7a8af30801ea46680bc783f9 for versions 1.0 through 1.1.
As a temporary mitigation, restrict access to the `generate host task()` function.