EIP-2026-104519

PRE-CVE

NetBSD 5.0 - Hack PATH Environment Overflow (PoC)

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-104519. PoCs published by JMIT.

AI-analyzed exploit summary This script exploits a stack-based buffer overflow in the 'hack' game on NetBSD 5.0 and below by overflowing the PATH environment variable. It uses a Perl command to generate a malicious payload and attempts to execute arbitrary code, though successful exploitation is noted as difficult.

Description

NetBSD 5.0 - Hack PATH Environment Overflow (PoC)

Exploits (1)

exploitdb WORKING POC
by JMIT · bashdosnetbsd_x86
https://www.exploit-db.com/exploits/12653

This script exploits a stack-based buffer overflow in the 'hack' game on NetBSD 5.0 and below by overflowing the PATH environment variable. It uses a Perl command to generate a malicious payload and attempts to execute arbitrary code, though successful exploitation is noted as difficult.

Classification
Working Poc 90%
Attack Type
Rce
Complexity
Moderate
Reliability
Theoretical
Target: NetBSD hack game (versions 5.0 and below)
No auth needed
Prerequisites: NetBSD 5.0 or below with the 'hack' game installed · Ability to set environment variables
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026