The tilde in your PATH may not be your HOME
First reported by Disconnect3d.pl ·
Shells now correctly expand the tilde character in your PATH variable to your home directory, preventing potential security risks.
A security vulnerability has been identified where the tilde character (~) in the PATH environment variable does not correctly expand to the user's home directory. This issue occurs when the tilde is used in unquoted strings within shell configuration files like .bashrc or .zshrc. Instead of expanding to a full path like /home/<user>/.local/bin, the PATH entry may remain as ~/.local/bin. This can lead to unexpected behavior, as demonstrated by the ability to create and execute a binary from a directory named '~/.local/bin' located in the current directory, not the user's home. The author found this issue while using the nono agent sandboxing tool, which alerted them to PATH entries it could write to. A fix involves explicitly using the $HOME variable, such as 'export PATH="$PATH:$HOME/.local/bin/"'.
This discovery highlights a subtle but potentially significant security pitfall in common shell configurations across Bash and Zsh. The failure to properly expand the tilde character can allow malicious actors or misconfigured scripts to execute unintended binaries from directories that coincidentally share names with home directory subfolders. Users who rely on tilde expansion in their PATH may unknowingly introduce vulnerabilities by allowing executables to be found in unexpected locations, potentially overshadowing legitimate system commands or user-installed utilities.
System administrators and security-conscious users should audit their shell configuration files for instances of tilde expansion in PATH definitions. Replacing '~' with '$HOME' is a straightforward remediation that ensures consistent and secure behavior across different shell environments and contexts. While the nono tool's warning is credited, the broader implication is the need for greater vigilance in how environment variables are constructed and interpreted, especially in security-sensitive operations like sandboxing.
AI-written summary. May contain errors.