Aiyiyi121 Sxdevops
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Aiyiyi121 Sxdevops.
By the Year
In 2026 there have been 7 vulnerabilities in Aiyiyi121 Sxdevops with an average score of 5.9 out of ten.
| Year | Vulnerabilities | Average Score |
|---|---|---|
| 2026 | 7 | 5.87 |
It may take a day or so for new Sxdevops vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Aiyiyi121 Sxdevops Security Vulnerabilities
aiyi yi121 SxDevOps 1.0/1.1 Remote Info Disclosure via settings.py
CVE-2026-93971
6.9 - Medium
- September 20, 2026
A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation causes information disclosure. It is possible to initiate the attack remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Information Disclosure
CVE-2026-93970: Hard-coded creds in aiyiyi121 SxDevOps 1.0 Settings Handler
CVE-2026-93970
6.9 - Medium
- September 20, 2026
A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote. The patch is identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Use of Hard-coded Credentials
Hard-Coded Credentials in aiiyi121 SxDevOps 1.01.1 rbac/services.py
CVE-2026-93969
6.9 - Medium
- September 20, 2026
A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be carried out remotely. The identifier of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is recommended to apply a patch to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Use of Hard-coded Credentials
SxDevOps 1.0/1.1 Privilege Escalation via UserSerializer update
CVE-2026-93968
5.1 - Medium
- September 20, 2026
A vulnerability was determined in aiyiyi121 SxDevOps 1.0/1.1. This affects the function update of the file backend/rbac/serializers.py of the component UserSerializer. Executing a manipulation can lead to improper privilege management. The attack can be executed remotely. This patch is called 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is best practice to apply a patch to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Improper Privilege Management
Command Handler in Aiyiyi121 SxDevOps 1.1: CMD Injection in generate_host_task
CVE-2026-93967
5.1 - Medium
- September 20, 2026
A vulnerability was found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this issue is the function generate_host_task of the file backend/aiops/services.py of the component Command Handler. Performing a manipulation of the argument command results in command injection. Remote exploitation of the attack is possible. The patch is named 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is the recommended action to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Command Injection
Command Injection in aiyiyi121 SxDevOps 1.0/1.1 via TASK_RUN exec_command
CVE-2026-93966
5.1 - Medium
- September 20, 2026
A vulnerability has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected by this vulnerability is the function paramiko.SSHClient.exec_command of the file backend/ops/host_tasks.py of the component TASK_RUN_COMMAND. Such manipulation of the argument command leads to command injection. The attack may be launched remotely. The name of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is advisable to implement a patch to correct this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Command Injection
Command Injection in aiyiyi121 SxDevOps 1.0/1.1 MCP STDIO Server Mgmt
CVE-2026-93965
5.1 - Medium
- September 20, 2026
A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. This manipulation of the argument endpoint_or_command causes command injection. The attack may be initiated remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. To fix this issue, it is recommended to deploy a patch. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Command Injection
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Aiyiyi121 Sxdevops or by Aiyiyi121? Click the Watch button to subscribe.