Description
`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by absolute path, so both are resolved through the `PATH` environment variable. A local attacker who is less privileged than the host application, and who can influence `PATH` or write to a directory that appears in `PATH` ahead of the system directories, can have an arbitrary binary executed in the application's security context, resulting in local code execution/privilege escalation. This vulnerability only affect macOS hosts - Linux and Windows hosts are unaffected. Version 1.16.0-beta.2 contains a patch. No known workarounds are available.
Published: 2026-09-08
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Local Code Execution
Action: Patch immediately
AI Analysis

Impact

The OpenTelemetry.Resources.Host NuGet package contains a host resource attribute detector that, before version 1.16.0-beta.2, executes the system commands "sh" and "ioreg" by their bare names instead of by absolute paths. On macOS, this causes the executables to be resolved through the PATH environment variable, creating an untrusted search path flaw. An attacker who can influence the PATH or write a malicious binary to a directory that appears earlier in PATH can have that binary run with the application's privileges, resulting in local code execution and potential privilege escalation. The vulnerability is defined by CWE‑426: Untrusted Search Path. The flaw is limited to macOS hosts; Linux and Windows releases are unaffected.

Affected Systems

The affected product is the OpenTelemetry.Resources.Host library provided by the open-telemetry organization, distributed as a NuGet package. Versions prior to 1.16.0-beta.2 are vulnerable. No other vendors are impacted at this time.

Risk and Exploitability

The CVSS score of 7 indicates moderate severity, and the lack of an EPSS score means a specific exploitation probability is not available from the CVSS calculator. Because the attack requires local access to modify PATH or write to a directory in PATH, it is limited to local attacks. The attacker must be less privileged than the target application but can still achieve code execution and potential privilege escalation. The vulnerability is not listed in CISA KEV, suggesting no confirmed exploitation cases to date. However, the local nature of the flaw and the simplicity of the exploitation path mean that, if an attacker gains any local foothold, this flaw can be rapidly leveraged.

Generated by OpenCVE AI on September 9, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the OpenTelemetry.Resources.Host NuGet package to version 1.16.0-beta.2 or later.
  • Modify the system PATH used by the application to exclude writable directories that could be tampered with by local attackers.
  • Monitor running processes for unexpected use of "sh" or "ioreg" and investigate any anomalies.

Generated by OpenCVE AI on September 9, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-v8pv-4842-x354 OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
History

Fri, 11 Sep 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Opentelemetry
Opentelemetry opentelemetry-dotnet-contrib
Vendors & Products Opentelemetry
Opentelemetry opentelemetry-dotnet-contrib

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Description `OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by absolute path, so both are resolved through the `PATH` environment variable. A local attacker who is less privileged than the host application, and who can influence `PATH` or write to a directory that appears in `PATH` ahead of the system directories, can have an arbitrary binary executed in the application's security context, resulting in local code execution/privilege escalation. This vulnerability only affect macOS hosts - Linux and Windows hosts are unaffected. Version 1.16.0-beta.2 contains a patch. No known workarounds are available.
Title OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Opentelemetry Opentelemetry-dotnet-contrib
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T15:43:01.911Z

Reserved: 2026-08-26T16:26:08.968Z

Link: CVE-2026-81192

cve-icon Vulnrichment

Updated: 2026-09-09T15:42:58.328Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T21:18:43.447

Modified: 2026-09-10T19:58:20.507

Link: CVE-2026-81192

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T03:45:18Z

Weaknesses