Arbitrary File Write Flaw in Classroom 50 Tool by Foundation50
CVE-2026-94620

9.4CRITICAL

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-94620?

Classroom 50, a free and open-source tool for managing programming assignments on GitHub, contains a vulnerability that allows arbitrary file writes. This issue arises prior to version 1.11.0, where the gh teacher download command can clone student repositories and inadvertently write files where symlinks lead. An attacker can exploit this by committing result.json or results.json as symlinks, redirecting writes to sensitive areas like user configuration files. Due to elevated permissions associated with the teacher's GitHub token, this flaw could potentially allow for code execution within the classroom organization. To mitigate the issue, it’s recommended to upgrade to version 1.11.0 or utilize sandbox environments when executing downloads from untrusted repositories.

Affected Version(s)

classroom50 < 1.11.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.