Impact
A flaw in the subprocess.Popen function of backend/aiops/services.py allows an attacker to manipulate the endpoint_or_command argument, leading to execution of arbitrary shell commands. The vulnerability is exploitable remotely, potentially compromising confidentiality, integrity, and availability. The flaw corresponds to CWE-74 and CWE-77 and has a CVSS score of 5.1, indicating a moderate risk level.
Affected Systems
The affected product is aiyiyi121 SxDevOps, version 1.0 and 1.1. The insecure behavior resides in the MCP STDIO Server Management component. A vendor‑supplied patch identified by commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9 is available to remediate the issue.
Risk and Exploitability
The CVSS score of 5.1 suggests moderate severity, but the vulnerability can be triggered from any remote client, implying a non‑restricted attack surface. The EPSS score is not available and the vulnerability is not listed in CISA KEV, yet the lack of exploitation data does not diminish the necessity of patching quickly. Until the patch is applied, an attacker could gain full system control through arbitrary command execution.
OpenCVE Enrichment