Skip to content
CVE-2026-93965: SxDevOps Injection (CVSS 6.6)

CVE-2026-93965: SxDevOps Injection (CVSS 6.6)

Strix.Ai September 20, 2026

CVE-2026-93965 is a medium-severity vulnerability rated 6.6/10 on the CVSS scale . A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management .

A flaw has been found in aiyiyi121 SxDevOps 1.0/1.1. Affected is the function subprocess.Popen of the file backend/aiops/services.py of the component MCP STDIO Server Management. This manipulation of the argument endpoint_or_command causes command injection. The attack may be initiated remotely. Patch name: 2b4bf8585c3e731e7a8af30801ea46680bc783f9. To fix this issue, it is recommended to deploy a patch. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L/E:X/RL:O/RC:C

Source: CNA advisory (CVE.org). NVD analysis pending.

Frequently Asked Questions

How Strix found a critical auth bypass in etcd Strix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.

Autonomous Pentesting AI agents that find and validate exploitable vulnerabilities like this one across your applications.

PR Reviews Pentest every pull request so vulnerable code is caught before it ships to production.

AI Penetration Testing How AI-driven penetration testing continuously covers your attack surface.

Related CVEs from 2026

CVE-2026-9396 A security flaw has been discovered in Besen BS20 EV Chargin… 3.7

CVE-2026-93960 A vulnerability was identified in Pixelfed up to 0.12.11. Im… 4.3

CVE-2026-93961 A security flaw has been discovered in Dromara UJCMS up to 1… 5.3

CVE-2026-93962 A weakness has been identified in Kamailio up to 5.8.8/6.0.7… 8.3

CVE-2026-93963 A security vulnerability has been detected in itsourcecode L… 6.3

CVE-2026-93964 A vulnerability was detected in NginxProxyManager nginx-prox… 5.3

CVE-2026-9397 A weakness has been identified in Besen BS20 EV Charging Sta… 8.2

CVE-2026-9398 A security vulnerability has been detected in Besen BS20 EV … 3.1

CVE-2026-93981 hono before 4.13.7 fails to HTML-escape plain strings render… 4.7

CVE-2026-93982 OpenPanel through commit bad75bdd writes Model Context Proto… 3.3

CVE-2026-93983 OpenPanel through commit bad75bdd fails to escape property k… 5

CVE-2026-93984 OpenPanel tracking API through commit bad75bddc74d12d36cfb84… 5.3

Are you affected by CVE-2026-93965 ?

Run a free Strix scan to check your systems for this vulnerability.