Skip to content

CVE lookup

CVE-2026-14891

Pruva has a verified reproduction for CVE-2026-14891: HashiCorp Nomad's Docker task driver can be tricked into bind-mounting host paths via a symlink containment bypass, enabling sandbox escape and host file read/write.. The canonical evidence record is REPRO-2026-00385.

REPRO

REPRO-2026-00385

Package

hashicorp/nomad · other

Severity

HIGH

Status

published