CVE-2026-93965: aiyiyi121 SxDevOps MCP STDIO Server Management services.py subprocess.Popen command injection
A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. This manipulation of the argument endpointorcommand causes command injection. The attack may be initiated remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. To fix this issue, it is recommended to deploy a patch. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
aiyiyi121 SxDevOps MCP STDIO Server Management (backend/aiops/services.py, subprocess.Popen)to a version that resolves this vulnerability.Patch 2b4bf8585c3e731e7a8af30801ea46680bc783f9 - Compensating control
Since the command injection may be initiated remotely, restrict network access to the MCP STDIO Server Management endpoint (e.g., allow only trusted sources) until the patch is deployed.
Event History
Frequently Asked Questions
Which deployments are affected?
The affected component is MCP STDIO Server Management in aiyiyi121 SxDevOps versions 1.0 and 1.1. The vulnerable code is in backend/aiops/services.py, where subprocess.Popen processes the endpoint_or_command argument.
What access does an attacker need to exploit this issue?
The issue can be initiated remotely and has low attack complexity, but the supplied severity vector indicates that an attacker needs high privileges. No user interaction is required.
Is a fix available?
Yes. The provided patch identifier is 2b4bf8585c3e731e7a8af30801ea46680bc783f9, and deployment of the patch is recommended.