在 aiYiYi121 SxDevOps 1.0/1.1 中发现一个安全漏洞。该漏洞影响的是组件 TASK_RUN_COMMAND 中 文件里 函数。攻击者可以通过操纵 参数引发命令注入漏洞,并且该攻击可远程发起。补丁编号为 2b4bf8585c3e731e7a8af30801ea46680bc783f9。建议实施该补丁以修复此问题。供应商在较早时间被联系后,以非常专业的方式迅速响应,并快速发布了受影响产品的修复版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-93970 | 7.3 HIGH | aiyiyi121 SxDevOps Settings settings.py hard-coded credentials |
| CVE-2026-93969 | 7.3 HIGH | aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials |
| CVE-2026-93965 | 6.6 MEDIUM | aiyiyi121 SxDevOps MCP STDIO Server Management services.py subprocess.Popen command inject |
| CVE-2026-93967 | 5.5 MEDIUM | aiyiyi121 SxDevOps Command services.py generate_host_task command injection |
| CVE-2026-93971 | 5.3 MEDIUM | aiyiyi121 SxDevOps settings.py information disclosure |
| CVE-2026-93968 | 3.8 LOW | aiyiyi121 SxDevOps UserSerializer serializers.py update privileges management |
No comments yet