Local Command Execution Flaw in Environment Modules by Red Hat
CVE-2026-85013

7.3HIGH

What is CVE-2026-85013?

A vulnerability in the environment-modules package allows local attackers to execute arbitrary commands by placing a carefully crafted module file in a directory within the victim's MODULEPATH. When a user employs Bash completion for module or ml commands, the maliciously named module is treated as a command due to the inclusion of shell metacharacters, potentially compromising the user's confidentiality, integrity, and availability. This flaw could have significant implications depending on the privileges of the victim.

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.