CVE-2026-93970: aiyiyi121 SxDevOps Settings settings.py hard-coded credentials
A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote. The patch is identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
aiyiyi121 SxDevOpsto a version that resolves this vulnerability.Patch 2b4bf8585c3e731e7a8af30801ea46680bc783f9
Event History
Frequently Asked Questions
Which releases are known to be affected?
The issue is reported in aiyiyi121 SxDevOps versions 1.0 and 1.1. The vulnerable code is in backend/sxdevops/settings.py within the Settings Handler.
Can this be exploited remotely without credentials or user interaction?
Yes. The supplied vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
What is the available remediation?
Apply the vendor patch identified as commit 2b4bf8585c3e731e7a8af30801ea46680bc783f9. The vendor also released a fixed version, though its version number is not provided.
How can I determine whether my deployment is affected?
Confirm whether the deployment uses SxDevOps 1.0 or 1.1, then inspect backend/sxdevops/settings.py and verify whether patch 2b4bf8585c3e731e7a8af30801ea46680bc783f9 has been applied.