Arbitrary File Write Flaw in Classroom 50 Tool by Foundation50
CVE-2026-94620
What is CVE-2026-94620?
Classroom 50, a free and open-source tool for managing programming assignments on GitHub, contains a vulnerability that allows arbitrary file writes. This issue arises prior to version 1.11.0, where the gh teacher download command can clone student repositories and inadvertently write files where symlinks lead. An attacker can exploit this by committing result.json or results.json as symlinks, redirecting writes to sensitive areas like user configuration files. Due to elevated permissions associated with the teacher's GitHub token, this flaw could potentially allow for code execution within the classroom organization. To mitigate the issue, it’s recommended to upgrade to version 1.11.0 or utilize sandbox environments when executing downloads from untrusted repositories.
Affected Version(s)
classroom50 < 1.11.0
