CVE-2026-85013

NameCVE-2026-85013
DescriptionA flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
modules (PTS)bookworm5.2.0-1vulnerable
trixie5.5.0-1vulnerable
forky5.6.2-1fixed
sid5.7.0-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
modulessource(unstable)5.6.1-3

Notes

[trixie] - modules <no-dsa> (Minor issue; will be fixed via point release)
[bookworm] - modules <postponed> (Minor issue, requires access to trusted local directory)
Fixed by: https://github.com/envmodules/modules/commit/d401b76a863386f9064637c71b66837805f82881 (v5.6.2)

Search for package or bug name: Reporting problems