Impact
The OpenTelemetry.Resources.Host NuGet package contains a host resource attribute detector that, before version 1.16.0-beta.2, executes the system commands "sh" and "ioreg" by their bare names instead of by absolute paths. On macOS, this causes the executables to be resolved through the PATH environment variable, creating an untrusted search path flaw. An attacker who can influence the PATH or write a malicious binary to a directory that appears earlier in PATH can have that binary run with the application's privileges, resulting in local code execution and potential privilege escalation. The vulnerability is defined by CWE‑426: Untrusted Search Path. The flaw is limited to macOS hosts; Linux and Windows releases are unaffected.
Affected Systems
The affected product is the OpenTelemetry.Resources.Host library provided by the open-telemetry organization, distributed as a NuGet package. Versions prior to 1.16.0-beta.2 are vulnerable. No other vendors are impacted at this time.
Risk and Exploitability
The CVSS score of 7 indicates moderate severity, and the lack of an EPSS score means a specific exploitation probability is not available from the CVSS calculator. Because the attack requires local access to modify PATH or write to a directory in PATH, it is limited to local attacks. The attacker must be less privileged than the target application but can still achieve code execution and potential privilege escalation. The vulnerability is not listed in CISA KEV, suggesting no confirmed exploitation cases to date. However, the local nature of the flaw and the simplicity of the exploitation path mean that, if an attacker gains any local foothold, this flaw can be rapidly leveraged.
OpenCVE Enrichment
Github GHSA