Static

The tilde in your PATH may not be your HOME

First reported by Disconnect3d.pl ·

The signal ●○○○ Compiled by AI from Disconnect3d.pl and Hacker News
Why you might care

Shells now correctly expand the tilde character in your PATH variable to your home directory, preventing potential security risks.

What happened

A security vulnerability has been identified where the tilde character (~) in the PATH environment variable does not correctly expand to the user's home directory. This issue occurs when the tilde is used in unquoted strings within shell configuration files like .bashrc or .zshrc. Instead of expanding to a full path like /home/<user>/.local/bin, the PATH entry may remain as ~/.local/bin. This can lead to unexpected behavior, as demonstrated by the ability to create and execute a binary from a directory named '~/.local/bin' located in the current directory, not the user's home. The author found this issue while using the nono agent sandboxing tool, which alerted them to PATH entries it could write to. A fix involves explicitly using the $HOME variable, such as 'export PATH="$PATH:$HOME/.local/bin/"'.

What it means

This discovery highlights a subtle but potentially significant security pitfall in common shell configurations across Bash and Zsh. The failure to properly expand the tilde character can allow malicious actors or misconfigured scripts to execute unintended binaries from directories that coincidentally share names with home directory subfolders. Users who rely on tilde expansion in their PATH may unknowingly introduce vulnerabilities by allowing executables to be found in unexpected locations, potentially overshadowing legitimate system commands or user-installed utilities.

System administrators and security-conscious users should audit their shell configuration files for instances of tilde expansion in PATH definitions. Replacing '~' with '$HOME' is a straightforward remediation that ensures consistent and secure behavior across different shell environments and contexts. While the nono tool's warning is credited, the broader implication is the need for greater vigilance in how environment variables are constructed and interpreted, especially in security-sensitive operations like sandboxing.

AI-written summary. May contain errors.

Tech