Tildes in Path Variables Break Shell Expansion Rules

PATH entries the sandbox can write to: ~/.local/bin/.

As disconnect3d.pl reported, inserting a tilde directly into your PATH variable inside files like ~/.bashrc or ~/.zshrc completely breaks standard shell expansion rules.

Why Shells Fail to Expand the Tilde in PATH Assignments

When you write export PATH="$PATH:~/.local/bin/", you are wrapping the assignment in double quotes. This stops the shell from doing its usual job.

According to official bash documentation, a word beginning with an unquoted tilde character triggers a tilde-prefix check up to the first unquoted slash. Bash explicitly checks variable assignments for unquoted tilde-prefixes immediately following a colon or the first equals sign. By wrapping the entire right side in double quotes, the shell bypasses that trigger.

Instead of appending your actual home directory to the path, you get a literal dot-slash-tilde directory. Your system ends up searching ./~/.local/bin/ relative to wherever you happen to be standing when you open a terminal.

How a Local Directory Hijacks Your Binary Execution

Security analysis shows you can easily demonstrate this behavior locally:

$ ls -la
total 0
drwxr-xr-x@  2 dc  staff   64 Oct  2 13:37 .
drwxr-x---+ 105 dc  staff 3360 Oct  2 13:37 ..
$ mkdir -p ./~/.local/bin/
$ printf '#include <stdio.h>nint main() { puts("hello"); }' > a.c; gcc a.c -o ./~/.local/bin/kek
$ PATH="~/.local/bin/" kek
hello
$ tree -f .
├── ./~
│   └── ./~/.local
│       └── ./~/.local/bin
│           └── ./~/.local/bin/kek
└── ./a.c
4 directories, 2 files

The compiled binary executes cleanly from the local directory. Your actual home directory is never involved.

How to Audit and Fix Your Configuration Files

Fixing the issue requires swapping out the tilde for the explicit environment variable. Changing the line to export PATH="$PATH:$HOME/.local/bin/" forces the shell to evaluate $HOME correctly inside the quoted string.

You can check if your environment suffers from this exact vulnerability by running a quick search against your current PATH variable:

$ echo "$PATH" | grep -- '~'

Alternatively, you can output each entry onto its own individual line to inspect them one by one:

$ echo "$PATH" | tr ':' 'n' | grep '~'

If that command returns any matches containing a tilde, open your .bashrc, .zshrc, or .profile immediately and update those entries.

Unix for Neuroimagers #4: Shells, Paths, and Variables
Photo of author

Sophie Lin - Technology Editor

Sophie is a tech innovator and acclaimed tech writer recognized by the Online News Association. She translates the fast-paced world of technology, AI, and digital trends into compelling stories for readers of all backgrounds.

NFL Star Christian McCaffrey and Olivia Culpo Welcome Second Child