目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CVE-2026-94620— Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)

一分钟漏洞结论

影响对象
foundation50 classroom50
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

Classroom 50 是一款免费且开源的工具,用于通过 GitHub 管理和批改编程作业。在版本 1.11.0 之前, 命令会克隆每位学生的作业仓库,并将自动评分生成的文件( 和 )写入刚刚克隆的工作树中。由于该写入操作会跟随符号链接(symlink),如果学生将 或 提交为符号链接( 会原样还原这些符号链接),就可以将教师的写入操作重定向到任意路径——例如 、 、cron 任务文件,或克隆仓库中 下的文件(Git 随后可能会执行这些钩子脚本)。所写入的内容由攻击者控制:对于 ,其内容来自学生上传的发布资产(r

CVSS 9.4 · Critical
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-94620 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)
来源: CVE Program / CVE List V5
Vulnerability Description
Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each student's assignment repository and then writes autograde artifacts (`result.json` and `results.json`) into the just-cloned working tree. The write followed symlinks, so a student who committed `result.json` or `results.json` as a **symlink** (materialized verbatim by `git clone`) could redirect the teacher's write to an arbitrary path — e.g. `~/.zshrc`, `~/.ssh/authorized_keys`, a cron file, or an in-clone `.git/hooks/*` file that git subsequently executes. The written bytes are attacker-controlled (the student's uploaded release asset for `result.json`; student-chosen submit-tag names for `results.json`). This is an arbitrary file write leading to code execution as the teacher, whose `gh` token carries `admin:org`, `repo`, and `workflow` across the entire classroom organization. Version 1.11.0 contains a patch. Some workarounds are available. Avoid running `gh teacher download` against untrusted student repositories, or run it inside a disposable sandbox / container with no access to sensitive host files or credentials. Inspect cloned trees for symlinked, hardlinked, or special (`result.json`/`results.json`) entries before allowing the artifact-refresh step to run.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
来源: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
foundation50 classroom50 < 1.11.0 -

二、漏洞 CVE-2026-94620 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-94620 的情报信息

请登录查看更多情报信息。

CVE-2026-94620 其他参考 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-94620

暂无评论


发表评论