PT-2026-95934 · Aiyiyi121 · Sxdevops

·

CVE-2026-93967

·

Published

2026-09-20

·

Updated

2026-09-20

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions aiyiyi121 SxDevOps versions 1.0 through 1.1
Description A command injection issue exists within the Command Handler component. The generate host task() function in the backend/aiops/services.py file fails to properly handle the command argument, allowing remote attackers to execute arbitrary commands.
Recommendations Apply patch 2b4bf8585c3e731e7a8af30801ea46680bc783f9 for versions 1.0 through 1.1. As a temporary mitigation, restrict access to the generate host task() function.

Exploit

Fix

Command Injection

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93967

Affected Products

Sxdevops