Or just set $PATH to a directory you control containing an "ls" binary. I don't understand what this post is on about at all - is it implying they've discovered a way to control environment variables of unrelated processes or users?
> We were also unable to control the contents of a file on disk
From the first and second sentence.
One wouldn't usually file a CVE in these circumstances, if only the client is affected.