Junglewise Threat Intelligence

CVE-2026-24051: OpenTelemetry Go SDK path hijacking in host_id.go on macOS

CVE-2026-24051 · Severity: high · CVSS 7 · Published 2026-02-02

Technologies: go.opentelemetry.io/otel/sdk (Go), Opentelemetry Go SDK, Opentelemetry. Vendors: Go, Opentelemetry.

Executive brief

OpenTelemetry is a popular framework used by developers to monitor and observe application performance. A security flaw in the Go version of this tool on macOS allows a local attacker to trick the software into running malicious code instead of standard system commands. This could lead to a full system compromise or unauthorized access to sensitive application data if an attacker has already gained limited access to the machine.

Technical details

A Path Hijacking (Untrusted Search Path) vulnerability exists in the OpenTelemetry Go SDK's resource detection logic on macOS/Darwin. Specifically, the code in `sdk/resource/host_id.go` attempts to execute the `ioreg` system command without specifying an absolute path. An attacker with local access and the ability to modify the PATH environment variable can place a malicious executable named `ioreg` in a directory searched before the legitimate system path. When the SDK executes, it will run the attacker's code with the privileges of the application process. This issue is addressed in version v1.40.0 by using the full absolute path for the command.

Affected products

  • OpenTelemetry OpenTelemetry Go SDK v1.20.0 - v1.39.0

Timeline

  • 2026-02-02: disclosed
  • 2026-02-02: advisory
  • 2026-02-02: patched: Fixed in version v1.40.0

References

Related threats