CVE-2026-94620
Received Received - Intake

Arbitrary File Write in Classroom 50

Vulnerability report for CVE-2026-94620, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: GitHub, Inc.

Description

Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each student's assignment repository and then writes autograde artifacts (`result.json` and `results.json`) into the just-cloned working tree. The write followed symlinks, so a student who committed `result.json` or `results.json` as a **symlink** (materialized verbatim by `git clone`) could redirect the teacher's write to an arbitrary path β€” e.g. `~/.zshrc`, `~/.ssh/authorized_keys`, a cron file, or an in-clone `.git/hooks/*` file that git subsequently executes. The written bytes are attacker-controlled (the student's uploaded release asset for `result.json`; student-chosen submit-tag names for `results.json`). This is an arbitrary file write leading to code execution as the teacher, whose `gh` token carries `admin:org`, `repo`, and `workflow` across the entire classroom organization. Version 1.11.0 contains a patch. Some workarounds are available. Avoid running `gh teacher download` against untrusted student repositories, or run it inside a disposable sandbox / container with no access to sensitive host files or credentials. Inspect cloned trees for symlinked, hardlinked, or special (`result.json`/`results.json`) entries before allowing the artifact-refresh step to run.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
github classroom 1.11.0
foundation50 classroom50 1.11.0
github gh_teacher to 1.11.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in Classroom 50 (versions before 1.11.0) allows a student to trick a teacher into overwriting arbitrary files on their system by exploiting symlinks in student repositories. When the teacher runs `gh teacher download`, the tool clones student repos and writes autograde files (`result.json` or `results.json`) into the cloned directory. If a student commits these filenames as symlinks pointing to sensitive files (like `~/.zshrc` or `~/.ssh/authorized_keys`), the teacher's write operation will overwrite those files instead. This leads to arbitrary file write and potential code execution as the teacher, who has elevated GitHub organization privileges.

Detection Guidance

Check for symlinks, hardlinks, or special files named result.json or results.json in cloned student repositories before running gh teacher download. Inspect repository contents for suspicious symlinks pointing to sensitive paths like ~/.zshrc or ~/.ssh/authorized_keys.

Impact Analysis

If you are a teacher using Classroom 50 before version 1.11.0, a malicious student could compromise your system by redirecting file writes to sensitive locations. This could allow them to overwrite critical files like shell configurations, SSH keys, or Git hooks, leading to full system access or remote code execution. The impact is severe because the teacher's GitHub token grants high privileges across the organization.

Compliance Impact

This vulnerability could lead to unauthorized access or modification of sensitive data, violating compliance requirements like GDPR (data protection) or HIPAA (health information security). If a teacher's system is compromised, attackers might gain access to protected student data or organizational resources, resulting in potential legal and regulatory penalties.

Mitigation Strategies

Upgrade to version 1.11.0 or later of Classroom 50. Avoid running gh teacher download against untrusted repositories. Run the command inside a disposable sandbox or container with no access to sensitive host files or credentials.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-94620. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart