CVE-2026-24051 | open-telemetry opentelemetry-go up to 1.39.x Environment Variable sdk/resource/host_id.go PATH untrusted search path (GHSA-9h8m-3fm2-qjrq)
A vulnerability, which was classified as problematic, was found in open-telemetry opentelemetry-go up to 1.39.x. Affected is an unknown function of the file sdk/resource/host_id.go of the component Environment Variable Handler. Executing a manipulation of the argument PATH can lead to untrusted search path.
This vulnerability is registered as CVE-2026-24051. The attack needs to be launched locally. No exploit is available.
You should upgrade the affected component.