EIP-2026-102814

PRE-CVE

Debian XTERM - 'DECRQSS/comments' Code Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102814. PoCs published by Paul Szabo.

AI-analyzed exploit summary This exploit leverages a vulnerability in xterm where the DECRQSS (Device Control Request Status String) feature improperly executes commands embedded in invalid DCS sequences. The PoC demonstrates command injection via a crafted escape sequence, which can be triggered by viewing a malicious log file or email.

Description

Debian XTERM - 'DECRQSS/comments' Code Execution

Exploits (1)

exploitdb WORKING POC VERIFIED
by Paul Szabo · textlocallinux
https://www.exploit-db.com/exploits/7681

This exploit leverages a vulnerability in xterm where the DECRQSS (Device Control Request Status String) feature improperly executes commands embedded in invalid DCS sequences. The PoC demonstrates command injection via a crafted escape sequence, which can be triggered by viewing a malicious log file or email.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: xterm version 222-1etch2
No auth needed
Prerequisites: Victim must view the crafted file or email containing the malicious escape sequence
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026