NomadGHSA-5mqx-rpxv-mvxj
HashiCorp Nomad is vulnerable to path escape through archive unpacking during migration
High7.7CVE-2024-6717 · Published Jul 23, 2024 · updated Feb 4, 2026
HashiCorp Nomad and Nomad Enterprise 1.6.12 up to 1.7.9, and 1.8.1 archive unpacking during migration is vulnerable to path escaping of the allocation directory. This vulnerability, CVE-2024-6717, is fixed in Nomad 1.6.13, 1.7.10, and 1.8.2.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| github.com/hashicorp/nomad Go | < 1.8.2 | 1.8.2 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-610
- Also known as
- CVE-2024-6717, GO-2026-4278
- nvd.nist.gov/vuln/detail/CVE-2024-6717
- github.com/hashicorp/nomad/commit/ef6cdec8847e0698d386d1fd3761743df758ef99
- discuss.hashicorp.com/t/hcsec-2024-15-nomad-vulnerable-to-allocation-directory-path-escape-through-archive-unpacking/68781
- github.com/hashicorp/nomad
- github.com/hashicorp/nomad/releases/tag/v1.8.2
More Nomad advisories
All Nomad| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 112025 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability | High8.1 | 1.10.2 |
| Mar 102025 | Nomad: secrets in logs | Medium6.5 | No fix yet |
| Dec 202024 | Hashicorp Nomad Incorrect Privilege Assignment vulnerability | Medium6.5 | 1.9.4 |
| Nov 72024 | Hashicorp Nomad Incorrect Authorization vulnerability | Medium7.7 | No fix yet |
| Aug 152024 | Nomad Vulnerable to Allocation Directory Escape On Non-Existing File Paths Through Archive Unpacking | Medium5.8 | 1.6.14+2 more |
| Feb 82024 | HashiCorp Nomad vulnerable to symlink attacks | High7.7 | 1.5.14+2 more |