Don't Put Tilde In Your Path

The article warns developers against using the tilde (~) character in PATH variable assignments within shell configuration files. It explains that tilde expansion behaves inconsistently in quoted strings, which can lead to security risks or broken execution paths.
Why it matters
Proper configuration of environment variables is critical for system security and preventing the accidental execution of malicious or unintended binaries.
I was playing with the nono agent sandboxing tool and it greeted me with a warning: PATH entries the sandbox can write to: ~/.local/bin/ which looked suspicious.
In other words, doing this in your ~/.bashrc or ~/.zshrc :
export PATH = " $PATH :~/.local/bin/" will not expand the ~ (tilde) into the home path (or $HOME ) as the tilde to home expansion happens only in unquoted inputs, as also the bash documentation says :
If a word begins with an unquoted tilde character (‘~’), all of the characters up to the first unquoted slash (…) are considered a tilde-prefix. (…)
Bash checks each variable assignment for unquoted tilde-prefixes immediately following a ‘:’ or the first ‘=’, and performs tilde expansion in these cases. (…)
So instead of having /home/<user>/.local/bin/ added to PATH we end up with ./~/.local/bin/ added to PATH .
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in