Command Injection Vulnerability in SxDevOps MCP STDIO Server Management by aiyiyi121
CVE-2026-93965
5.1MEDIUM
What is CVE-2026-93965?
A critical flaw exists in the SxDevOps MCP STDIO Server Management component, specifically in the subprocess.Popen function within backend/aiops/services.py. This security issue allows attackers to exploit vulnerable parameters, resulting in command injection attacks that can be triggered remotely. Users are urged to apply the patch provided by the vendor, which addresses this issue promptly and effectively, ensuring better security for the affected versions.
Affected Version(s)
SxDevOps 1.0
SxDevOps 1.1
