GHSA-v8pv-4842-x354
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
Quick fix
GHSA-v8pv-4842-x354 — OpenTelemetry.Resources.Host: upgrade to the fixed version with the command below.
dotnet add package OpenTelemetry.Resources.Host --version 1.16.0-beta.2Details
### Summary
The `OpenTelemetry.Resources.Host` NuGet package is affected by an untrusted search path vulnerability on macOS. The `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by absolute path, so both are resolved through the `PATH` environment variable.
A local attacker who is less privileged than the host application, and who can influence `PATH` or write to a directory that appears in `PATH` ahead of the system directories, can have an arbitrary binary executed in the application's security context, resulting in local code execution/privilege escalation.
### Details
The implementation of the host detector macOS has always invoked `ioreg` and `sh` via their bare names since it was implemented by [open-telemetry/opentelemetry-dotnet-contrib#1631](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/1631).
The vulnerability was fixed by [open-telemetry/opentelemetry-dotnet-contrib#4760](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4760) which executes `ioreg` directly using its absolute path.
### Impact
Applications running on **macOS** that use the `OpenTelemetry.Resources.Host` detector when an attacker who is *less privileged* than the application process can influence `PATH` or write to a `PATH` directory that precedes the system directories (e.g. a higher-privileged service with a user-writable directory in its search path, or a process inheriting an attacker-influenced environment). The attacker gains code execution in the application's security context through an attacker-controlled `ioreg` executable.
### Mitigation
This vulnerability only affect macOS hosts - Linux and Windows hosts are unaffected.
### Workarounds
None known.
### References
- [GHSA-9h8m-3fm2-qjrq](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-9h8m-3fm2-qjrq) - [open-telemetry/opentelemetry-dotnet-contrib#4760](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4760) - [CWE-426](https://cwe.mitre.org/data/definitions/426.html)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.16.0-beta.2dotnet add package OpenTelemetry.Resources.Host --version 1.16.0-beta.2References
- https://github.com/open-telemetry/opentelemetry-dotnet-contrib/security/advisories/GHSA-v8pv-4842-x354[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-81192[ADVISORY]
- https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/1631[WEB]
- https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4760[WEB]
- https://github.com/open-telemetry/opentelemetry-dotnet-contrib[PACKAGE]