CVE-2026-93971: aiyiyi121 SxDevOps settings.py information disclosure
A weakness has been identified in aiyiyi121 SxDevOps 1.0/1.1. Impacted is an unknown function of the file backend/sxdevops/settings.py. This manipulation causes information disclosure. It is possible to initiate the attack remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
aiyiyi121 SxDevOps 1.0/1.1to a version that resolves this vulnerability.Patch 2b4bf8585c3e731e7a8af30801ea46680bc783f9 - Compensating control
Since the issue can be initiated remotely and leads to information disclosure, restrict network access to the service that hosts aiyiyi121 SxDevOps so only trusted clients can reach it.
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be initiated remotely over the network. It does not require prior privileges or user interaction.
What is the expected impact of successful exploitation?
The reported impact is information disclosure with low confidentiality impact. No integrity or availability impact is reported.
Which installations should be remediated?
aiyiyi121 SxDevOps versions 1.0 and 1.1 are identified as affected. Prioritize deployments that are reachable over the network.
What remediation is available?
Apply the vendor patch identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. The available data does not name the fixed product version.