{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aopentelemetryopentelemetry_resources_host/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:opentelemetry:opentelemetry_resources_host:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7,"id":"CVE-2026-81192"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenTelemetry.Resources.Host (\u003c 1.16.0-beta.2)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OpenTelemetry"],"content_html":"\u003cp\u003eThe OpenTelemetry.Resources.Host NuGet package (versions prior to 1.16.0-beta.2) contains an untrusted search path vulnerability on macOS, tracked as CVE-2026-81192. The \u003ccode\u003ehost.id\u003c/code\u003e resource attribute detector initiates the \u003ccode\u003eioreg\u003c/code\u003e and \u003ccode\u003esh\u003c/code\u003e system binaries using bare names rather than absolute file paths. This implementation relies on the system's \u003ccode\u003ePATH\u003c/code\u003e environment variable to locate the executables.\u003c/p\u003e\n\u003cp\u003eA local, less-privileged attacker capable of modifying the \u003ccode\u003ePATH\u003c/code\u003e environment variable or placing a malicious executable into a directory that appears earlier in the \u003ccode\u003ePATH\u003c/code\u003e than system directories can intercept the execution request. When the host application - which may be running with elevated privileges - triggers the detector, it unknowingly executes the attacker-supplied binary. This results in arbitrary code execution within the context of the application process. Defenders should prioritize updating the library to the patched version, as the vulnerability is specific to macOS environments and no effective workarounds exist.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker gains access to a user account on a macOS system where a vulnerable application is installed.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a process or service utilizing the \u003ccode\u003eOpenTelemetry.Resources.Host\u003c/code\u003e package.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a writable directory that is included in the \u003ccode\u003ePATH\u003c/code\u003e variable used by the targeted process.\u003c/li\u003e\n\u003cli\u003eAttacker writes a malicious executable named \u003ccode\u003eioreg\u003c/code\u003e to that directory.\u003c/li\u003e\n\u003cli\u003eAttacker modifies the environment variables of the targeted process or waits for the process to restart with the hijacked \u003ccode\u003ePATH\u003c/code\u003e configuration.\u003c/li\u003e\n\u003cli\u003eThe targeted application invokes the \u003ccode\u003ehost.id\u003c/code\u003e resource attribute detector.\u003c/li\u003e\n\u003cli\u003eThe system resolves the call for \u003ccode\u003eioreg\u003c/code\u003e to the malicious binary provided by the attacker.\u003c/li\u003e\n\u003cli\u003eThe application executes the malicious binary with the application's elevated permissions, granting the attacker code execution.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThis vulnerability allows for local privilege escalation on macOS systems. If an application using the affected library runs as root or another highly privileged service user, an attacker can achieve code execution at that elevated level. This facilitates full system compromise, data theft, and persistent access within the target environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the \u003ccode\u003eOpenTelemetry.Resources.Host\u003c/code\u003e NuGet package to version 1.16.0-beta.2 or later immediately. Ensure that environment variable configurations for critical services are hardened to prevent unauthorized modification of the \u003ccode\u003ePATH\u003c/code\u003e variable. There are currently no known configuration workarounds for this vulnerability.\u003c/p\u003e\n","date_modified":"2026-09-16T19:07:58Z","date_published":"2026-09-16T19:07:58Z","id":"https://feed.craftedsignal.io/briefs/2026-09-opentelemetry-host-path-hijack/","summary":"The OpenTelemetry.Resources.Host NuGet package is vulnerable to arbitrary code execution on macOS due to the use of bare paths for system command execution, allowing PATH hijacking.","title":"Untrusted Search Path Vulnerability in OpenTelemetry.Resources.Host on macOS","url":"https://feed.craftedsignal.io/briefs/2026-09-opentelemetry-host-path-hijack/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:opentelemetry:opentelemetry_resources_host:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}