Description
HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to code execution on the client host through a path traversal attack. This vulnerability (CVE-2026-7474) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.
Problem types
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Product status
1.10.0 (semver) before 2.0.1
1.10.0 (semver) before 2.0.1
Credits
This issue was reported to HashiCorp by Adrian Denkiewicz at Doyensec in collaboration with Claude and Anthropic Research
References
discuss.hashicorp.com/...ch-may-lead-to-code-execution/77417