aiyi yi121 SxDevOps 1.0/1.1 Remote Info Disclosure via settings.py
CVE-2026-93971 Published on September 20, 2026

aiyiyi121 SxDevOps settings.py information disclosure
A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation causes information disclosure. It is possible to initiate the attack remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

NVD

Timeline

Advisory disclosed

VulDB entry created

VulDB entry last update

Weakness Types

What is an Information Disclosure Vulnerability?

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CVE-2026-93971 has been classified to as an Information Disclosure vulnerability or weakness.

What is an Authorization Vulnerability?

The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

CVE-2026-93971 has been classified to as an Authorization vulnerability or weakness.


Products Associated with CVE-2026-93971

Want to know whenever a new CVE is published for Aiyiyi121 Sxdevops? stack.watch will email you.

 

Affected Versions

aiyiyi121 SxDevOps: