GHSA-9h8m-3fm2-qjrq

Suggest an improvement
Source
https://github.com/advisories/GHSA-9h8m-3fm2-qjrq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-9h8m-3fm2-qjrq/GHSA-9h8m-3fm2-qjrq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9h8m-3fm2-qjrq
Aliases
Downstream
CGA (3450)
MINI (553)
Published
2026-02-02T20:07:46Z
Modified
2026-09-10T03:50:34Z
Severity
  • 7.0 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking
Details

Impact

The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application.

Patches

This has been patched in d45961b, which was released with v1.40.0.

References

Database specific
{
    "cwe_ids":  [
        "CWE-426"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-02-02T20:07:46Z",
    "nvd_published_at":  "2026-02-02T23:16:07Z",
    "severity":  "HIGH"
}
References

Affected packages

Go / go.opentelemetry.io/otel/sdk

Package

Name
go.opentelemetry.io/otel/sdk
View open source insights on deps.dev
Purl
pkg:golang/go.opentelemetry.io/otel/sdk

Affected ranges

Type
SEMVER
Events
Introduced
1.21.0
Fixed
1.40.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/02/GHSA-9h8m-3fm2-qjrq/GHSA-9h8m-3fm2-qjrq.json"