Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
To mitigate this issue, avoid enabling Bash completion for `module` and `ml` in environments where untrusted users can influence `MODULEPATH`. Additionally, ensure that shared module search paths do not include attacker-writable directories. As a practical measure, the affected completion script can be removed or disabled by commenting out its sourcing in shell configuration files (e.g., `~/.bashrc` or `/etc/profile.d/`). Users must start a new shell session for changes to take effect.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 15 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability. | |
| Title | Environment-modules: command injection in environment-modules bash completion via malicious module names containing shell metacharacters | |
| First Time appeared |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:/a:redhat:hummingbird:1 cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:6 cpe:/o:redhat:enterprise_linux:7 cpe:/o:redhat:enterprise_linux:8 cpe:/o:redhat:enterprise_linux:9 |
|
| Vendors & Products |
Redhat
Redhat enterprise Linux Redhat hummingbird |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-15T15:08:33.907Z
Reserved: 2026-09-02T19:15:03.876Z
Link: CVE-2026-85013
No data.
No data.
No data.
OpenCVE Enrichment
No data.
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')