Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9h8m-3fm2-qjrq | OpenTelemetry Go SDK Vulnerable to Arbitrary Code Execution via PATH Hijacking |
Fri, 27 Feb 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Linuxfoundation
Linuxfoundation opentelemetry-go |
|
| CPEs | cpe:2.3:a:linuxfoundation:opentelemetry-go:*:*:*:*:*:go:*:* | |
| Vendors & Products |
Linuxfoundation
Linuxfoundation opentelemetry-go |
Wed, 04 Feb 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opentelemetry
Opentelemetry opentelemetry |
|
| Vendors & Products |
Opentelemetry
Opentelemetry opentelemetry |
Tue, 03 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Feb 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenTelemetry-Go is the Go implementation of OpenTelemetry. The OpenTelemetry Go SDK in version v1.20.0-1.39.0 is vulnerable to Path Hijacking (Untrusted Search Paths) on macOS/Darwin systems. The resource detection code in sdk/resource/host_id.go executes the ioreg system command using a search path. An attacker with the ability to locally modify the PATH environment variable can achieve Arbitrary Code Execution (ACE) within the context of the application. A fix was released with v1.40.0. | |
| Title | OpenTelemetry-Go Affected by Arbitrary Code Execution via PATH Hijacking | |
| Weaknesses | CWE-426 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-03T14:54:41.668Z
Reserved: 2026-01-20T22:30:11.778Z
Link: CVE-2026-24051
Updated: 2026-02-03T14:54:37.009Z
Status : Analyzed
Published: 2026-02-02T23:16:07.963
Modified: 2026-02-27T20:32:10.693
Link: CVE-2026-24051
No data.
OpenCVE Enrichment
Updated: 2026-04-18T00:45:32Z
Github GHSA