Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9h8m-3fm2-qjrq

Опубликовано: 02 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7

Описание

OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking

Impact

The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application.

Patches

This has been patched in d45961b, which was released with v1.40.0.

References

Пакеты

Наименование

go.opentelemetry.io/otel/sdk/resource

go
Затронутые версииВерсия исправления

>= 1.21.0, <= 1.39.0

1.40.0

EPSS

Процентиль: 0%
0.00006
Низкий

7 High

CVSS3

Дефекты

CWE-426

Связанные уязвимости

CVSS3: 7
ubuntu
4 дня назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.

CVSS3: 7
nvd
4 дня назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.

CVSS3: 7
debian
4 дня назад

OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTe ...

EPSS

Процентиль: 0%
0.00006
Низкий

7 High

CVSS3

Дефекты

CWE-426