HashiCorp Nomad’s exec2 task driver vulnerable to a symlink attack
Moderate severity
GitHub Reviewed
Published
May 12, 2026
to the GitHub Advisory Database
•
Updated May 19, 2026
Package
Affected versions
< 0.1.2
Patched versions
0.1.2
Description
Published by the National Vulnerability Database
May 12, 2026
Published to the GitHub Advisory Database
May 12, 2026
Reviewed
May 19, 2026
Last updated
May 19, 2026
HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.
References