EIP-2026-102993

PRE-CVE

shadowsocks-libev 3.1.0 - Command Execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-102993. PoCs published by X41 D-Sec GmbH.

AI-analyzed exploit summary This advisory describes a command execution vulnerability in Shadowsocks-libev's ss-manager component, where malicious commands can be injected via the 'method' parameter in JSON configuration files or UDP requests. The vulnerability arises from improper handling of user-supplied input in the 'construct_command_line' function, leading to arbitrary command execution.

Description

shadowsocks-libev 3.1.0 - Command Execution

Exploits (1)

exploitdb WRITEUP
by X41 D-Sec GmbH · textlocallinux
https://www.exploit-db.com/exploits/43006

This advisory describes a command execution vulnerability in Shadowsocks-libev's ss-manager component, where malicious commands can be injected via the 'method' parameter in JSON configuration files or UDP requests. The vulnerability arises from improper handling of user-supplied input in the 'construct_command_line' function, leading to arbitrary command execution.

Classification
Writeup 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Shadowsocks-libev 3.1.0
No auth needed
Prerequisites: Access to UDP port 8839 on 127.0.0.1 or ability to modify configuration files
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026