Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-94620— Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)

Quick assessment

Affected
foundation50 classroom50
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Classroom 50 是一款免费且开源的工具,用于通过 GitHub 管理和批改编程作业。在版本 1.11.0 之前, 命令会克隆每位学生的作业仓库,并将自动评分生成的文件( 和 )写入刚刚克隆的工作树中。由于该写入操作会跟随符号链接(symlink),如果学生将 或 提交为符号链接( 会原样还原这些符号链接),就可以将教师的写入操作重定向到任意路径——例如 、 、cron 任务文件,或克隆仓库中 下的文件(Git 随后可能会执行这些钩子脚本)。所写入的内容由攻击者控制:对于 ,其内容来自学生上传的发布资产(r

CVSS 9.4 · Critical EPSS 0.41% · P34

Affected Version Matrix 1

VendorProduct Version RangeStatus
foundation50 classroom50 < 1.11.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-94620

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)
Source: CVE Program / CVE List V5
Vulnerability Description
Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each student's assignment repository and then writes autograde artifacts (`result.json` and `results.json`) into the just-cloned working tree. The write followed symlinks, so a student who committed `result.json` or `results.json` as a **symlink** (materialized verbatim by `git clone`) could redirect the teacher's write to an arbitrary path — e.g. `~/.zshrc`, `~/.ssh/authorized_keys`, a cron file, or an in-clone `.git/hooks/*` file that git subsequently executes. The written bytes are attacker-controlled (the student's uploaded release asset for `result.json`; student-chosen submit-tag names for `results.json`). This is an arbitrary file write leading to code execution as the teacher, whose `gh` token carries `admin:org`, `repo`, and `workflow` across the entire classroom organization. Version 1.11.0 contains a patch. Some workarounds are available. Avoid running `gh teacher download` against untrusted student repositories, or run it inside a disposable sandbox / container with no access to sensitive host files or credentials. Inspect cloned trees for symlinked, hardlinked, or special (`result.json`/`results.json`) entries before allowing the artifact-refresh step to run.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
foundation50 classroom50 < 1.11.0 -

II. Public POCs for CVE-2026-94620

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-94620

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-94620 (1)

Vendor Advisories for CVE-2026-94620 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-94620

No comments yet


Leave a comment