Description
A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SSHClient.exec_command of the file backend/ops/host_tasks.py of the component TASK_RUN_COMMAND. Such manipulation of the argument command leads to command injection. The attack may be launched remotely. The name of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is advisable to implement a patch to correct this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-09-20
Score: 5.1 Medium
EPSS: 1.6% Low
KEV: No
Impact: Command injection
Action: Patch Now
AI Analysis

Impact

Aiyiyi121 SxDevOps host_tasks.py uses paramiko.SSHClient.exec_command without validating the command string, allowing an attacker to inject arbitrary shell commands. This flaw can lead to remote execution of malicious code on the host machine, resulting in full system compromise, data theft, or service disruption.

Affected Systems

SxDevOps versions 1.0 and 1.1 expose the TASK_RUN_COMMAND endpoint, which calls the vulnerable function. Any deployment that allows external actors to invoke this endpoint is vulnerable.

Risk and Exploitability

The CVSS score of 5.1 indicates moderate severity. EPSS score of 2% and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote, as the description states the attack may be launched remotely. Exploitation would require access to the TASK_RUN_COMMAND interface, likely protected by authentication and network reachability. Overall risk remains moderate, but a successful exploit results in significant compromise.

Generated by OpenCVE AI on September 20, 2026 at 14:41 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install the patch corresponding to commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9 to address the command injection flaw.
  • Restrict access to the TASK_RUN_COMMAND API by implementing firewall rules or network segmentation to limit traffic to trusted hosts and enforce authentication.
  • Enable logging and monitoring for host_tasks.py executions to detect abnormal command activity and investigate potential unauthorized execution attempts.

Generated by OpenCVE AI on September 20, 2026 at 14:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SSHClient.exec_command of the file backend/ops/host_tasks.py of the component TASK_RUN_COMMAND. Such manipulation of the argument command leads to command injection. The attack may be launched remotely. The name of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is advisable to implement a patch to correct this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title aiyiyi121 SxDevOps TASK_RUN_COMMAND host_tasks.py paramiko.SSHClient.exec_command command injection
First Time appeared Aiyiyi121
Aiyiyi121 sxdevops
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:aiyiyi121:sxdevops:*:*:*:*:*:*:*:*
Vendors & Products Aiyiyi121
Aiyiyi121 sxdevops
References
Metrics cvssV2_0

{'score': 5.8, 'vector': 'AV:N/AC:L/Au:M/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 4.7, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Aiyiyi121 Sxdevops
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-21T15:05:25.571Z

Reserved: 2026-09-19T10:14:47.749Z

Link: CVE-2026-93966

cve-icon Vulnrichment

Updated: 2026-09-21T15:05:21.098Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T07:16:51.563

Modified: 2026-09-21T15:17:36.400

Link: CVE-2026-93966

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:50Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')