Untrusted Search Path Affecting opentelemetry.resources.host package, versions [,1.16.0-beta.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.14% (4th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DOTNET-OPENTELEMETRYRESOURCESHOST-19651704
  • published9 Sept 2026
  • disclosed8 Sept 2026
  • creditUnknown

Introduced: 8 Sep 2026

NewCVE-2026-81192  (opens in a new tab)
CWE-426  (opens in a new tab)

How to fix?

Upgrade OpenTelemetry.Resources.Host to version 1.16.0-beta.2 or higher.

Overview

Affected versions of this package are vulnerable to Untrusted Search Path through the macOS host detector command execution in HostDetector.cs. An attacker can execute arbitrary code in the application's security context by supplying a malicious ioreg binary earlier in PATH and triggering the host.id resource detection on macOS. This affects applications that run the detector with a user-influenced search path, allowing local privilege escalation or code execution when the process launches the command by bare name.

CVSS Base Scores

version 4.0
version 3.1