EIP-2026-120637

PRE-CVE

ZSH 5.9 - RCE

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-120637. PoCs published by sinanadilrana.

AI-analyzed exploit summary This exploit leverages a memory corruption vulnerability in ZSH 5.9 to achieve remote code execution (RCE) by manipulating memory addresses and injecting a reverse shell payload via GDB. It uses pexpect to automate GDB interactions, demonstrating a functional exploit chain.

Description

ZSH 5.9 - RCE

Exploits (1)

exploitdb WORKING POC
by sinanadilrana · pythonlocallinux
https://www.exploit-db.com/exploits/52503

This exploit leverages a memory corruption vulnerability in ZSH 5.9 to achieve remote code execution (RCE) by manipulating memory addresses and injecting a reverse shell payload via GDB. It uses pexpect to automate GDB interactions, demonstrating a functional exploit chain.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: ZSH 5.9
No auth needed
Prerequisites: GDB with pwndbg · ZSH 5.9 binary · network connectivity to attacker-controlled IP
devstral-2 · analyzed Apr 10, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Apr 10, 2026