FWIW, I tried changing "echo vulnerable" to "whoami" and it didn't work. In fact, it segfaulted!
Maybe a path issue? Try it with
On the system I tested, I do get a segfault but only after it has run the command. It's definitely not limited to built-in commands; "/usr/bin/man bash" worked just fine.