Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 20 Sep 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. This manipulation of the argument endpoint_or_command causes command injection. The attack may be initiated remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. To fix this issue, it is recommended to deploy a patch. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | |
| Title | aiyiyi121 SxDevOps MCP STDIO Server Management services.py subprocess.Popen command injection | |
| First Time appeared |
Aiyiyi121
Aiyiyi121 sxdevops |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:a:aiyiyi121:sxdevops:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aiyiyi121
Aiyiyi121 sxdevops |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-09-20T05:45:10.959Z
Reserved: 2026-09-19T10:14:44.452Z
Link: CVE-2026-93965
No data.
Status : Received
Published: 2026-09-20T06:16:50.713
Modified: 2026-09-20T06:16:50.713
Link: CVE-2026-93965
No data.
OpenCVE Enrichment
No data.