THREAT OPS › Threat News › [GHSA] GHSA-v8pv-4842-x354 (high) — OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
[GHSA] GHSA-v8pv-4842-x354 (high) — OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
GHSA-v8pv-4842-x354 Severity: high CVE: CVE-2026-81192
OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOS
### Summary
The `OpenTelemetry.Resources.Host` NuGet package is affected by an untrusted search path vulnerability on macOS. The `host.id` resource attribute detector launches the `sh` and `ioreg` executables by bare name rather than by abs
Indicators of compromise
- CVE-2026-81192cve
Original source: https://github.com/advisories/GHSA-v8pv-4842-x354