High severity7.3NVD Advisory· Published Sep 15, 2026· Updated Sep 15, 2026
CVE-2026-85013
CVE-2026-85013
Description
A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's MODULEPATH. When the victim uses Bash completion for module or ml commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.
Affected products
1Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.