There is 1 open security issue in trixie.
1 issue left for the package maintainer to handle:
- CVE-2026-85013:
(needs triaging)
A flaw was found in environment-modules. A local attacker can exploit this vulnerability by placing a maliciously named modulefile in a location visible to the victim's `MODULEPATH`. When the victim uses Bash completion for `module` or `ml` commands, the malicious module name, containing shell metacharacters, is evaluated as a command. This can lead to arbitrary command execution in the completing user's shell, impacting their confidentiality, integrity, and availability.
You can find information about how to handle this issue in the security team's documentation.