Impact
A vulnerability in environment-modules allows a local attacker to inject shell metacharacters into a module completion for the `module` and `ml` commands. The flaw relies on CWE‑78, a command injection weakness, and can lead to arbitrary command execution in the shell of the user performing the completion, exposing that user's confidentiality, integrity, and availability.
Affected Systems
The issue impacts instances of environment-modules installed on Red Hat Enterprise Linux 10, 6, 7, 8, 9 and Red Hat Hardened Images. Any environment that uses Bash completion for the `module` or `ml` commands and has untrusted users able to influence the `MODULEPATH` is affected.
Risk and Exploitability
This is a local threat that requires attacker control over a directory listed in the victim's `MODULEPATH`. The CVSS score of 7.3 indicates a high severity, while the EPSS score indicates a very low likelihood of exploitation, less than 1%, suggesting that exploitation incidence is limited. The vulnerability is not listed in the CISA KEV catalog, but since the attack vector is local, it may be leveraged in privileged or compromised workstations where the user can trigger Bash completion. The path to exploitation is straightforward: publish a maliciously named module file, then have a user invoke the completion command, causing the shell to execute the injected commands.
OpenCVE Enrichment