Description
A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.
Published: 2026-09-15
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Command Execution via Bash Completion
Action: Patch Now
AI Analysis

Impact

A vulnerability in environment-modules allows a local attacker to inject shell metacharacters into a module completion for the `module` and `ml` commands. The flaw relies on CWE‑78, a command injection weakness, and can lead to arbitrary command execution in the shell of the user performing the completion, exposing that user's confidentiality, integrity, and availability.

Affected Systems

The issue impacts instances of environment-modules installed on Red Hat Enterprise Linux 10, 6, 7, 8, 9 and Red Hat Hardened Images. Any environment that uses Bash completion for the `module` or `ml` commands and has untrusted users able to influence the `MODULEPATH` is affected.

Risk and Exploitability

This is a local threat that requires attacker control over a directory listed in the victim's `MODULEPATH`. The CVSS score of 7.3 indicates a high severity, while the EPSS score indicates a very low likelihood of exploitation, less than 1%, suggesting that exploitation incidence is limited. The vulnerability is not listed in the CISA KEV catalog, but since the attack vector is local, it may be leveraged in privileged or compromised workstations where the user can trigger Bash completion. The path to exploitation is straightforward: publish a maliciously named module file, then have a user invoke the completion command, causing the shell to execute the injected commands.

Generated by OpenCVE AI on September 20, 2026 at 16:44 UTC.

Remediation

Vendor Workaround

To mitigate this issue, avoid enabling Bash completion for `module` and `ml` in environments where untrusted users can influence `MODULEPATH`. Additionally, ensure that shared module search paths do not include attacker-writable directories. As a practical measure, the affected completion script can be removed or disabled by commenting out its sourcing in shell configuration files (e.g., `~/.bashrc` or `/etc/profile.d/`). Users must start a new shell session for changes to take effect.


OpenCVE Recommended Actions

  • Disable Bash completion for `module` and `ml` by commenting out or removing the sourcing lines in shell configuration files such as `~/.bashrc` or `/etc/profile.d/`; then restart the shell.
  • Ensure that the directories referenced in `MODULEPATH` are not writable by untrusted or non‑privileged users; configure permissions or move them to a secure location.
  • Check with Red Hat for an updated environment‑modules package or Red Hat security advisory that removes the command‑injection flaw, and apply the patch as soon as it becomes available.

Generated by OpenCVE AI on September 20, 2026 at 16:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
References

Wed, 16 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Tue, 15 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.
Title Environment-modules: command injection in environment-modules bash completion via malicious module names containing shell metacharacters
First Time appeared Redhat
Redhat enterprise Linux
Redhat hummingbird
Weaknesses CWE-78
CPEs cpe:/a:redhat:hummingbird:1
cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
Redhat hummingbird
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux Hummingbird
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-09-21T11:43:06.327Z

Reserved: 2026-09-02T19:15:03.876Z

Link: CVE-2026-85013

cve-icon Vulnrichment

Updated: 2026-09-15T17:20:48.416Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T16:17:34.543

Modified: 2026-09-21T12:17:21.263

Link: CVE-2026-85013

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-15T14:10:00Z

Links: CVE-2026-85013 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T16:45:07Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')