A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's MODULEPATH. When the victim uses Bash completion for module or ml commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.
To mitigate this issue, avoid enabling Bash completion for module and ml in environments where untrusted users can influence MODULEPATH. Additionally, ensure that shared module search paths do not include attacker-writable directories. As a practical measure, the affected completion script can be removed or disabled by commenting out its sourcing in shell configuration files (e.g., ~/.bashrc or /etc/profile.d/). Users must start a new shell session for changes to take effect.