OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0.
CVSS Details
- CVSS 3.1 Base Score: 7
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Splunk | — | Upgrade Splunk Enterprise to version 10.0.7Upgrade Splunk Enterprise to version 9.4.13Upgrade Splunk Enterprise to version 10.0.8Upgrade Splunk Enterprise to version 9.3.13Upgrade Splunk Enterprise to version 10.2.4Upgrade Splunk Enterprise to version 10.4.0Upgrade Splunk Enterprise to version 10.4.1Upgrade Splunk Enterprise to version 10.2.5Upgrade Splunk Enterprise to version 9.4.12 | Jun 12, 2026 | Feb 2, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub