Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 20 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the file backend/aiops/services.py of the component Command Handler. Performing a manipulation of the argument command results in command injection. Remote exploitation of the attack is possible. The patch is named 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | |
| Title | aiyiyi121 SxDevOps Command services.py generate_host_task command injection | |
| First Time appeared |
Aiyiyi121
Aiyiyi121 sxdevops |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:a:aiyiyi121:sxdevops:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aiyiyi121
Aiyiyi121 sxdevops |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-20T06:15:11.195Z
Reserved: 2026-09-19T10:14:51.245Z
Link: CVE-2026-93967
No data.
No data.
No data.
OpenCVE Enrichment
No data.
