Hacker News new | ask | show | jobs
by chimeracoder 4296 days ago
> Unless there is an escalation exploit, worst case is that the code trashes your user's home folder.

Which is where your $PATH is often contained.

If an attacker can modify your $PATH (and has write-access to $HOME), you're pretty much done for.