Impact
Aiyiyi121 SxDevOps host_tasks.py uses paramiko.SSHClient.exec_command without validating the command string, allowing an attacker to inject arbitrary shell commands. This flaw can lead to remote execution of malicious code on the host machine, resulting in full system compromise, data theft, or service disruption.
Affected Systems
SxDevOps versions 1.0 and 1.1 expose the TASK_RUN_COMMAND endpoint, which calls the vulnerable function. Any deployment that allows external actors to invoke this endpoint is vulnerable.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS score of 2% and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote, as the description states the attack may be launched remotely. Exploitation would require access to the TASK_RUN_COMMAND interface, likely protected by authentication and network reachability. Overall risk remains moderate, but a successful exploit results in significant compromise.
OpenCVE Enrichment