CVE-2026-85013

high
Assigned by CNA: redhat
Published 2026-09-15 · Modified 2026-09-15
CVSS v3
7.3
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVSS v4 NEW
not yet in upstream
VIR risk
7.3

Description

A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.

Predictions

Exploit likelihood
72%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2026-85013 NameCVE-2026-85013 SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) Vulnerable and fixed packages The table below lists information on source packages. Source PackageReleaseVersionStatus modules (PTS)bookworm5.2.0-1vulnerable trixie5.5.0-1vulnerable forky5.6.1-3fixed…

CVE-2026-85013

NameCVE-2026-85013
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
modules (PTS)bookworm5.2.0-1vulnerable
trixie5.5.0-1vulnerable
forky5.6.1-3fixed
sid5.6.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
modulessource(unstable)5.6.1-3

Notes

[trixie] - modules <no-dsa> (Minor issue; will be fixed via point release)
Fixed by: https://github.com/envmodules/modules/commit/d401b76a863386f9064637c71b66837805f82881 (v5.6.2)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[trixie] - modules <no-dsa> (Minor issue; will be fixed via point release)Fixed by: https://github.com/envmodules/modules/commit/d401b76a863386f9064637c71b66837805f82881 (v5.6.2)

OS impact

debian Debian Mixed 4 releases
VersionStatusFixed in
trixie Affected
sid Fixed 5.6.1-3
forky Fixed 5.6.1-3
bookworm Affected

References

CWEs

CWE-78

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.