CVE-2026-93965: aiyiyi121 SxDevOps MCP STDIO Server Management services.py subprocess.Popen command injection

Published Sep 20, 2026
·
Updated

A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. This manipulation of the argument endpointorcommand causes command injection. The attack may be initiated remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. To fix this issue, it is recommended to deploy a patch. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

Affected Software

1 affected component
aiyiyi121 SxDevOps MCP STDIO Server Management>=1.0<=1.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade aiyiyi121 SxDevOps MCP STDIO Server Management (backend/aiops/services.py, subprocess.Popen) to a version that resolves this vulnerability.

    Patch 2b4bf8585c3e731e7a8af30801ea46680bc783f9
  2. Compensating control

    Since the command injection may be initiated remotely, restrict network access to the MCP STDIO Server Management endpoint (e.g., allow only trusted sources) until the patch is deployed.

Event History

Sep 20, 2026
CVE Published
via MITRE·05:45 AM
Data Sourced
via MITRE·05:45 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are affected?

The affected component is MCP STDIO Server Management in aiyiyi121 SxDevOps versions 1.0 and 1.1. The vulnerable code is in backend/aiops/services.py, where subprocess.Popen processes the endpoint_or_command argument.

2

What access does an attacker need to exploit this issue?

The issue can be initiated remotely and has low attack complexity, but the supplied severity vector indicates that an attacker needs high privileges. No user interaction is required.

3

Is a fix available?

Yes. The provided patch identifier is 2b4bf8585c3e731e7a8af30801ea46680bc783f9, and deployment of the patch is recommended.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203