Impact
A command injection flaw exists in the generate_host_task function of backend/aiops/services.py within SxDevOps 1.0/1.1. An attacker that can manipulate the command argument can cause arbitrary shell commands to be executed on the host. The weakness is a classic command injection (CWE‑74) that manifests as OS command injection (CWE‑77) and can compromise confidentiality, integrity and availability of the affected system. Remote exploitation is explicitly documented.
Affected Systems
The vulnerable component is aiyiyi121’s SxDevOps product, versions 1.0 and 1.1. The product is distributed via the GitHub repository aiyiyi121/sxdevops and the patched version is identified by the commit hash 2b4bf8585c3e731e7a8af30801ea46680bc783f9.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk level. EPSS data is not available, and the vulnerability has not been listed in CISA’s KEV catalog. Remote attackers can exploit the issue by sending a crafted command argument to the Command Handler; no privilege escalation is required, but successful exploitation grants the attacker full command execution on the host.
OpenCVE Enrichment