Vulnerability GHSA-9h8m-3fm2-qjrq
High Risk
HIGH RISK
CVSS Score: 7.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
8 months ago
February 02, 2026 at 08:07 PM UTC
OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking
v1.21.0 - v1.39.0
v1.21.0 - v1.39.0
Summary
OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking
Details
Impact
The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application.
Patches
This has been patched in d45961b, which was released with v1.40.0.
References
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
1 day ago
OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
v1.10.0 - v1.32.0 GHSA-p9f8-wvj8-2fg8
v1.10.0 - v1.32.0 GHSA-p9f8-wvj8-2fg8
Low Risk
13 days ago
OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
v1.5.0 - v1.44.0 GHSA-8wmf-6v46-5gfg
v1.5.0 - v1.44.0 GHSA-8wmf-6v46-5gfg
Unknown
2 months ago
Opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking in go.opentelemetry.io/otel/sdk
v1.15.0 - v1.42.0 GO-2026-5426
v1.15.0 - v1.42.0 GO-2026-5426
High Risk
5 months ago
opentelemetry-go: BSD kenv command not using absolute path enables PATH hijacking
v1.15.0 - v1.42.0 GHSA-hfvc-g4fc-pqhx
v1.15.0 - v1.42.0 GHSA-hfvc-g4fc-pqhx
Unknown
7 months ago
OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking in go.opentelemetry.io/otel/sdk
v1.21.0 - v1.39.0 GO-2026-4394
v1.21.0 - v1.39.0 GO-2026-4394
Impacted packages
Timeline
Published
8 months ago
February 02, 2026 at 08:07 PM UTC
Last Modified
20 days ago
September 10, 2026 at 03:50 AM UTC