Executive brief
HashiCorp Nomad is a workload orchestrator used to deploy and manage applications across data centers. A security flaw in its 'Dynamic Host Volumes' feature allows an authorized user to trick the system into running unauthorized programs on the host server. This could lead to a complete takeover of the server, potentially exposing sensitive data or disrupting business operations.
Technical details
A path traversal vulnerability (CWE-22) exists in HashiCorp Nomad's Dynamic Host Volumes workflow. When a user with 'host-volume-create' and node read access submits a request, they can manipulate the 'plugin_id' parameter. Because the Nomad agent joins this ID to the plugin directory path without sufficient validation, an attacker can use traversal sequences (e.g., ../) to execute arbitrary binaries located outside the intended plugin directory. These binaries are executed with the same privileges as the Nomad agent, typically root. The issue is fixed in versions 2.0.1, 1.11.5, and 1.10.11 by implementing 'os.Root' checks and enforcing server-side plugin validation even when a specific node ID is provided.
Affected products
- HashiCorp Nomad 1.10.0 to 2.0.0, fixed in 2.0.1, 1.11.5, and 1.10.11
- HashiCorp Nomad Enterprise 1.10.0 to 2.0.0, fixed in 2.0.1, 1.11.5, and 1.10.11
Timeline
- 2026-05-12: disclosed
- 2026-05-12: patched
- 2026-05-12: advisory