CVE-2020-10944: Hashicorp Nomad

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

HashiCorp Nomad and Nomad Enterprise up to 0.10.4 contained a cross-site scripting vulnerability such that files from a malicious workload could cause arbitrary JavaScript to execute in the web UI. Fixed in 0.10.5.

Affected products

  • Hashicorp Nomad: from 0.3, before 0.10.5 (fixed in 0.10.5)

Published 2020-04-28. Last modified 2026-06-17.