{"id":"GHSA-wqwc-x3rc-2xw6","summary":"HashiCorp Nomad’s exec2 task driver vulnerable to a symlink attack","details":"HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-8052) is fixed in version 0.1.2 of the exec2 task driver.","aliases":["CVE-2026-8052","GO-2026-5718"],"modified":"2026-06-25T23:11:22.060267770Z","published":"2026-05-12T21:31:35Z","database_specific":{"nvd_published_at":"2026-05-12T20:16:46Z","cwe_ids":["CWE-59"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-05-19T15:39:35Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-8052"},{"type":"WEB","url":"https://discuss.hashicorp.com/t/hcsec-2026-13-nomads-exec2-task-driver-vulnerable-to-arbitrary-file-read-write-on-client-host-through-symlink-attack/77415"},{"type":"PACKAGE","url":"https://github.com/hashicorp/nomad-driver-exec2"},{"type":"WEB","url":"https://github.com/hashicorp/nomad-driver-exec2/releases/tag/v0.1.2"}],"affected":[{"package":{"name":"github.com/hashicorp/nomad-driver-exec2","ecosystem":"Go","purl":"pkg:golang/github.com/hashicorp/nomad-driver-exec2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.1.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-wqwc-x3rc-2xw6/GHSA-wqwc-x3rc-2xw6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N"}]}