Vulnerability  ·  2026-09-21

SxDevOps MCP STDIO server management — command injection via endpoint_or_command (CVE-2026-93965)

VulnerabilityLow impactGlobalCVE-2026-93965
NVD published CVE-2026-93965 on 2026-09-20 (CVSS 6.6): command injection in SxDevOps' MCP server-management services. A fix is available as patch 2b4bf8585c3e731e7a8af30801ea46680bc783f9.
A command-injection flaw in an MCP tool that manages server processes: in an agentic deployment, a prompt-injected agent invoking this tool (or a malicious MCP client) can escalate to OS-level command execution on the DevOps server.
The MCP 'MCP STDIO Server Management' component passes the endpoint_or_command argument to subprocess.Popen without neutralization (CWE-77/74), allowing a caller to inject operating-system commands. The vendor responded and released a patch.
aiyiyi121 SxDevOps 1.0/1.1 (backend/aiops/services.py, MCP STDIO Server Management)
Deploy patch 2b4bf8585c3e731e7a8af30801ea46680bc783f9. https://vuldb.com/cve/CVE-2026-93965
NVD CVE-2026-93965NVD CVE-2026-94031NVD CVE-2026-94044
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →