Solus has/had some hilariously bad exploits.
The slaves didn't/don't actually validate/scrub any of the data the master node sends and they simply push the data to shell_exec() with a root SETUID binary.
You could quite literally pass the slave a CTID (should only ever be an unsigned int) of...