{"affected":[{"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-v8pv-4842-x354/GHSA-v8pv-4842-x354.json"},"package":{"ecosystem":"NuGet","name":"OpenTelemetry.Resources.Host","purl":"pkg:nuget/OpenTelemetry.Resources.Host"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"1.16.0-beta.2"}],"type":"ECOSYSTEM"}]}],"aliases":["CVE-2026-81192"],"database_specific":{"cwe_ids":["CWE-426"],"github_reviewed":true,"github_reviewed_at":"2026-09-16T13:54:16Z","nvd_published_at":"2026-09-08T21:18:43Z","severity":"HIGH"},"details":"### Summary\n\nThe `OpenTelemetry.Resources.Host` NuGet package is affected by an untrusted search path vulnerability on macOS. The `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by absolute path, so both are resolved\nthrough the `PATH` environment variable.\n\nA local attacker who is less privileged than the host application, and who can influence `PATH` or write to a directory that appears in `PATH` ahead of the system directories, can have an arbitrary binary executed in the application's security context, resulting in local\ncode execution/privilege escalation.\n\n### Details\n\nThe implementation of the host detector macOS has always invoked `ioreg` and `sh` via their bare names since it was implemented by [open-telemetry/opentelemetry-dotnet-contrib#1631](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/1631).\n\nThe vulnerability was fixed by [open-telemetry/opentelemetry-dotnet-contrib#4760](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4760) which executes `ioreg` directly using its absolute path.\n\n### Impact\n\nApplications running on **macOS** that use the `OpenTelemetry.Resources.Host` detector when an attacker who is *less privileged* than the application process can influence `PATH` or write to a `PATH` directory that precedes the system directories (e.g. a higher-privileged service with a user-writable directory in its search path, or a process inheriting an attacker-influenced environment). The attacker gains code execution in the application's security context through an attacker-controlled `ioreg` executable.\n\n### Mitigation\n\nThis vulnerability only affect macOS hosts - Linux and Windows hosts are unaffected.\n\n### Workarounds\n\nNone known.\n\n### References\n\n- [GHSA-9h8m-3fm2-qjrq](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-9h8m-3fm2-qjrq)\n- [open-telemetry/opentelemetry-dotnet-contrib#4760](https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4760)\n- [CWE-426](https://cwe.mitre.org/data/definitions/426.html)","id":"GHSA-v8pv-4842-x354","modified":"2026-09-16T14:00:04.957357011Z","published":"2026-09-16T13:54:16Z","references":[{"type":"WEB","url":"https://github.com/open-telemetry/opentelemetry-dotnet-contrib/security/advisories/GHSA-v8pv-4842-x354"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-81192"},{"type":"WEB","url":"https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/1631"},{"type":"WEB","url":"https://github.com/open-telemetry/opentelemetry-dotnet-contrib/pull/4760"},{"type":"PACKAGE","url":"https://github.com/open-telemetry/opentelemetry-dotnet-contrib"}],"schema_version":"1.9.0","severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"}],"summary":"OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS"}