—
GO-2026-5718
HashiCorp Nomad’s exec2 task driver vulnerable to a symlink attack in github.com/hashicorp/nomad-driver-exec2
Quick fix
GO-2026-5718 — github.com/hashicorp/nomad-driver-exec2: upgrade to the fixed version with the command below.
go get github.com/hashicorp/nomad-driver-exec2@v0.1.2Details
HashiCorp Nomad’s exec2 task driver vulnerable to a symlink attack in github.com/hashicorp/nomad-driver-exec2
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/hashicorp/nomad-driver-exec2
Introduced in:
0Fixed in: 0.1.2Fix
go get github.com/hashicorp/nomad-driver-exec2@v0.1.2References
- https://github.com/advisories/GHSA-wqwc-x3rc-2xw6[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-8052[ADVISORY]
- https://discuss.hashicorp.com/t/hcsec-2026-13-nomads-exec2-task-driver-vulnerable-to-arbitrary-file-read-write-on-client-host-through-symlink-attack/77415[WEB]
- https://github.com/hashicorp/nomad-driver-exec2/releases/tag/v0.1.2[WEB]