CVE-2026-85013: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Red Hat Red Hat Enterprise Linux 10
A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.
AI Analysis
Technical Summary
The vulnerability exists in environment-modules on Red Hat Enterprise Linux 10, where Bash completion scripts for the 'module' and 'ml' commands improperly evaluate module names containing shell metacharacters as commands. A local attacker who can place a maliciously named modulefile in a directory included in the victim's MODULEPATH can trigger arbitrary command execution when the victim uses Bash completion. This flaw requires local access with low privileges and user interaction. The vulnerability is classified as OS command injection (CWE-78) and has a CVSS v3.1 score of 7.3 (High). The vendor advisory recommends avoiding enabling Bash completion for these commands in environments where untrusted users can influence MODULEPATH and removing or disabling the affected completion scripts.
Potential Impact
Successful exploitation allows a local attacker to execute arbitrary operating system commands with the privileges of the victim user running the shell. This can lead to full compromise of confidentiality, integrity, and availability of the victim's environment. The attack requires local access and user interaction but can result in unauthorized code execution, data modification, or denial of service.
Mitigation Recommendations
Red Hat advises to mitigate this vulnerability by avoiding enabling Bash completion for 'module' and 'ml' commands in environments where untrusted users can influence MODULEPATH. Additionally, ensure that shared module search paths do not include directories writable by attackers. As a practical measure, the affected Bash completion script can be disabled or removed by commenting out its sourcing in shell configuration files such as '~/.bashrc' or '/etc/profile.d/'. Users must start a new shell session for these changes to take effect. No official patch or fix is currently indicated in the advisory; check the vendor advisory for updates.
CVE-2026-85013: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Red Hat Red Hat Enterprise Linux 10
Description
A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.
CVSS v3.1
Score 7.3high
Affected software
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 6
Red Hat
Red Hat Enterprise Linux 7
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 9
Red Hat
Red Hat Hardened Images
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in environment-modules on Red Hat Enterprise Linux 10, where Bash completion scripts for the 'module' and 'ml' commands improperly evaluate module names containing shell metacharacters as commands. A local attacker who can place a maliciously named modulefile in a directory included in the victim's MODULEPATH can trigger arbitrary command execution when the victim uses Bash completion. This flaw requires local access with low privileges and user interaction. The vulnerability is classified as OS command injection (CWE-78) and has a CVSS v3.1 score of 7.3 (High). The vendor advisory recommends avoiding enabling Bash completion for these commands in environments where untrusted users can influence MODULEPATH and removing or disabling the affected completion scripts.
Potential Impact
Successful exploitation allows a local attacker to execute arbitrary operating system commands with the privileges of the victim user running the shell. This can lead to full compromise of confidentiality, integrity, and availability of the victim's environment. The attack requires local access and user interaction but can result in unauthorized code execution, data modification, or denial of service.
Mitigation Recommendations
Red Hat advises to mitigate this vulnerability by avoiding enabling Bash completion for 'module' and 'ml' commands in environments where untrusted users can influence MODULEPATH. Additionally, ensure that shared module search paths do not include directories writable by attackers. As a practical measure, the affected Bash completion script can be disabled or removed by commenting out its sourcing in shell configuration files such as '~/.bashrc' or '/etc/profile.d/'. Users must start a new shell session for these changes to take effect. No official patch or fix is currently indicated in the advisory; check the vendor advisory for updates.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-09-02T19:15:03.876Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-85013","vendor":"Red Hat"}]
Threat ID: 6aa9651655bf5e2cf502e933
Added to database: 09/15/2026, 15:32:38 UTC
Last enriched: 09/15/2026, 16:03:08 UTC
Last updated: 09/16/2026, 02:23:33 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.