๐Ÿ” CVE Alert

CVE-2026-93965

MEDIUM 6.6

aiyiyi121 SxDevOps MCP STDIO Server Management services.py subprocess.Popen command injection

CVSS Score
6.6
EPSS Score
0.0%
EPSS Percentile
0th

A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. This manipulation of the argument endpoint_or_command causes command injection. The attack may be initiated remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. To fix this issue, it is recommended to deploy a patch. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CWE CWE-77 CWE-74
Vendor aiyiyi121
Product sxdevops
Published Sep 20, 2026
Stay Ahead of the Next One

Get instant alerts for aiyiyi121 sxdevops

Be the first to know when new medium vulnerabilities affecting aiyiyi121 sxdevops are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

aiyiyi121 / SxDevOps
1.0 1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/407924 vuldb.com: https://vuldb.com/vuln/407924/cti vuldb.com: https://vuldb.com/cve/CVE-2026-93965 vuldb.com: https://vuldb.com/submit/944376 github.com: https://github.com/aiyiyi121/sxdevops/issues/16 github.com: https://github.com/aiyiyi121/sxdevops/commit/2b4bf8585c3e731e7a8af30801ea46680bc783f9 github.com: https://github.com/aiyiyi121/sxdevops/

Credits

๐Ÿ” _lxf (VulDB User) VulDB CNA Team