Junglewise Threat Intelligence

CVE-2026-93971: aiyiyi121 SxDevOps information disclosure in settings.py

CVE-2026-93971 · Severity: medium · CVSS 5.3 · Published 2026-09-20

Technologies: Aiyiyi121 SxDevOps. Vendors: Aiyiyi121.

Executive brief

SxDevOps is an open-source intelligent operations platform for infrastructure management. A weakness in the settings configuration file allows remote attackers to disclose sensitive information without authentication. The vendor has released a patch to address this vulnerability.

Technical details

An information disclosure vulnerability exists in backend/sxdevops/settings.py in SxDevOps versions 1.0 and 1.1, accessible via an unknown function. The vulnerability can be exploited remotely without requiring authentication or user interaction. A patch (commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9) hardens security controls and is available from the vendor.

Affected products

  • aiyiyi121 SxDevOps 1.0, 1.1

Timeline

  • 2026-09-20: disclosed
  • 2026-09-06: patched

References

Related threats