Junglewise Threat Intelligence

CVE-2026-93967: aiyiyi121 SxDevOps command injection in generate_host_task

CVE-2026-93967 · Severity: medium · CVSS 5.5 · Published 2026-09-20

Technologies: Aiyiyi121 SxDevOps. Vendors: Aiyiyi121.

Executive brief

SxDevOps is an open-source intelligent operations platform that automates infrastructure management workflows. A command injection vulnerability in the task management function allows an authenticated attacker to execute arbitrary commands on the server, potentially compromising the entire infrastructure being managed.

Technical details

The generate_host_task function in backend/aiops/services.py (the Command Handler component) fails to properly sanitize the command argument, allowing command injection attacks. Exploitation requires network access and valid authentication to the platform. A successful exploit enables remote code execution with the privileges of the SxDevOps application, and a patch (commit 2b4bf85) is available from the vendor.

Affected products

  • aiyiyi121 SxDevOps 1.0, 1.1

Timeline

  • 2026-09-20: disclosed
  • 2026-09-06: patched: Commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9

References

Related threats