CVE-2026-85013
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Summary
A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's MODULEPATH. When the victim uses Bash completion for module or ml commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.
Affected Software
| Vendor | Product | Version Range | Status |
|---|
Weaknesses
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Workarounds
To mitigate this issue, avoid enabling Bash completion for module and ml in environments where untrusted users can influence MODULEPATH. Additionally, ensure that shared module search paths do not include attacker-writable directories. As a practical measure, the affected completion script can be removed or disabled by commenting out its sourcing in shell configuration files (e.g., ~/.bashrc or /etc/profile.d/). Users must start a new shell session for changes to take effect.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: total
Additional References
References
- https://access.redhat.com/security/cve/CVE-2026-85013
- https://bugzilla.redhat.com/show_bug.cgi?id=2465635
- https://github.com/envmodules/modules/security/advisories/GHSA-8hrw-p88g-qhmg
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.