Executive brief
SxDevOps is an open-source intelligent operations platform for infrastructure management. A weakness in the settings configuration file allows remote attackers to disclose sensitive information without authentication. The vendor has released a patch to address this vulnerability.
Technical details
An information disclosure vulnerability exists in backend/sxdevops/settings.py in SxDevOps versions 1.0 and 1.1, accessible via an unknown function. The vulnerability can be exploited remotely without requiring authentication or user interaction. A patch (commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9) hardens security controls and is available from the vendor.
Affected products
- aiyiyi121 SxDevOps 1.0, 1.1
Timeline
- 2026-09-20: disclosed
- 2026-09-06: patched