Once you are passing arbitrary strings to bash as root -- yeah it's gonna be game over. This reminds me of the time a pentester found an XSS vuln and spent the entire rest of the engagement stuffing a keylogger into it. Like, OK, thanks, we already understand the implications of XSS.
The solution provided is suboptimal because all the focus is spent in making a good exploit demo instead of considering the root cause(s): the configuration of ssh, sudo, and the godawful shell script the author dredged up from parts unknown.
As I have seen this style of script being used with forced commands in authorized_keys, my conclusion is that the author loosely followed some online guide for restricting SSH access to certain commands and either inherited the flawed original script or made the error adapting it to the local requirements.
Proper options for restricting the shell abound. From the top of my head: rssh, sshdo, PolicyKit, rbash, rush