{"data":{"id":"c1d3fbfa-e895-43fb-aee4-6de9aa7ee1fa","title":"GHSA-v8pv-4842-x354: OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS","summary":"The OpenTelemetry.Resources.Host NuGet package on macOS has a vulnerability where it launches programs using bare names instead of absolute paths, allowing a less-privileged attacker to hijack the PATH environment variable (the list of directories the system searches for programs) and execute malicious code with the application's permissions. This vulnerability does not affect Linux or Windows systems.","solution":"The vulnerability was fixed by pull request open-telemetry/opentelemetry-dotnet-contrib#4760, which executes `ioreg` directly using its absolute path instead of relying on the PATH environment variable.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-v8pv-4842-x354","publishedAt":"2026-09-16T13:54:16.000Z","cveId":"CVE-2026-81192","cweIds":null,"cvssScore":null,"cvssSeverity":"high","severity":"high","attackType":["supply_chain"],"issueType":"vulnerability","affectedPackages":["OpenTelemetry.Resources.Host@< 1.16.0-beta.2 (fixed: 1.16.0-beta.2)"],"affectedVendors":[],"affectedVendorsRaw":["OpenTelemetry"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00138,"patchAvailable":true,"disclosureDate":"2026-09-16T13:54:16.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":["AML.T0010"]}}