Vulnerability GHSA-9h8m-3fm2-qjrq

High Risk
HIGH RISK
CVSS Score: 7.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
8 months ago
February 02, 2026 at 08:07 PM UTC
OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking
v1.21.0 - v1.39.0
v1.21.0 - v1.39.0

Summary

OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking

Details

Impact

The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application.

Patches

This has been patched in d45961b, which was released with v1.40.0.

References

Timeline

Published
8 months ago
February 02, 2026 at 08:07 PM UTC
Last Modified
20 days ago
September 10, 2026 at 03:50 AM UTC