Description
A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the file backend/aiops/services.py of the component Command Handler. Performing a manipulation of the argument command results in command injection. Remote exploitation of the attack is possible. The patch is named 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-09-20
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Command Execution
Action: Patch Immediately
AI Analysis

Impact

A command injection flaw exists in the generate_host_task function of backend/aiops/services.py within SxDevOps 1.0/1.1. An attacker that can manipulate the command argument can cause arbitrary shell commands to be executed on the host. The weakness is a classic command injection (CWE‑74) that manifests as OS command injection (CWE‑77) and can compromise confidentiality, integrity and availability of the affected system. Remote exploitation is explicitly documented.

Affected Systems

The vulnerable component is aiyiyi121’s SxDevOps product, versions 1.0 and 1.1. The product is distributed via the GitHub repository aiyiyi121/sxdevops and the patched version is identified by the commit hash 2b4bf8585c3e731e7a8af30801ea46680bc783f9.

Risk and Exploitability

The CVSS score of 5.1 indicates a moderate risk level. EPSS data is not available, and the vulnerability has not been listed in CISA’s KEV catalog. Remote attackers can exploit the issue by sending a crafted command argument to the Command Handler; no privilege escalation is required, but successful exploitation grants the attacker full command execution on the host.

Generated by OpenCVE AI on September 20, 2026 at 07:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor patch (commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9) to upgrade SxDevOps to a fixed version.
  • Restrict remote access to the Command Handler endpoint, for example by firewall rules or restricting service exposure, until the patch is applied.
  • Implement input validation or sanitization on the command argument to prevent injection, ensuring only permitted commands or arguments are accepted.

Generated by OpenCVE AI on September 20, 2026 at 07:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 22 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 20 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the file backend/aiops/services.py of the component Command Handler. Performing a manipulation of the argument command results in command injection. Remote exploitation of the attack is possible. The patch is named 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title aiyiyi121 SxDevOps Command services.py generate_host_task command injection
First Time appeared Aiyiyi121
Aiyiyi121 sxdevops
Weaknesses CWE-74
CWE-77
CPEs cpe:2.3:a:aiyiyi121:sxdevops:*:*:*:*:*:*:*:*
Vendors & Products Aiyiyi121
Aiyiyi121 sxdevops
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 5.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Aiyiyi121 Sxdevops
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-22T16:09:07.996Z

Reserved: 2026-09-19T10:14:51.245Z

Link: CVE-2026-93967

cve-icon Vulnrichment

Updated: 2026-09-22T16:09:02.344Z

cve-icon NVD

Status : Deferred

Published: 2026-09-20T07:16:51.920

Modified: 2026-09-22T17:17:30.997

Link: CVE-2026-93967

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:02:48Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')