Exploitation Summary
EIP tracks 1 public exploit for EIP-2026-102993. PoCs published by X41 D-Sec GmbH.
AI-analyzed exploit summary This advisory describes a command execution vulnerability in Shadowsocks-libev's ss-manager component, where malicious commands can be injected via the 'method' parameter in JSON configuration files or UDP requests. The vulnerability arises from improper handling of user-supplied input in the 'construct_command_line' function, leading to arbitrary command execution.
Description
shadowsocks-libev 3.1.0 - Command Execution
Exploits (1)
This advisory describes a command execution vulnerability in Shadowsocks-libev's ss-manager component, where malicious commands can be injected via the 'method' parameter in JSON configuration files or UDP requests. The vulnerability arises from improper handling of user-supplied input in the 'construct_command_line' function, leading to arbitrary command execution.