Executive brief
SxDevOps is an open-source intelligent operations platform that automates infrastructure management workflows. A command injection vulnerability in the task management function allows an authenticated attacker to execute arbitrary commands on the server, potentially compromising the entire infrastructure being managed.
Technical details
The generate_host_task function in backend/aiops/services.py (the Command Handler component) fails to properly sanitize the command argument, allowing command injection attacks. Exploitation requires network access and valid authentication to the platform. A successful exploit enables remote code execution with the privileges of the SxDevOps application, and a patch (commit 2b4bf85) is available from the vendor.
Affected products
- aiyiyi121 SxDevOps 1.0, 1.1
Timeline
- 2026-09-20: disclosed
- 2026-09-06: patched: Commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9