{"id":"CVE-2026-94620","summary":"Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)","details":"Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, `gh teacher download` clones each student's assignment repository and then writes autograde artifacts (`result.json` and `results.json`) into the just-cloned working tree. The write followed symlinks, so a student who committed `result.json` or `results.json` as a **symlink** (materialized verbatim by `git clone`) could redirect the teacher's write to an arbitrary path — e.g. `~/.zshrc`, `~/.ssh/authorized_keys`, a cron file, or an in-clone `.git/hooks/*` file that git subsequently executes. The written bytes are attacker-controlled (the student's uploaded release asset for `result.json`; student-chosen submit-tag names for `results.json`). This is an arbitrary file write leading to code execution as the teacher, whose `gh` token carries `admin:org`, `repo`, and `workflow` across the entire classroom organization. Version 1.11.0 contains a patch. Some workarounds are available. Avoid running `gh teacher download` against untrusted student repositories, or run it inside a disposable sandbox / container with no access to sensitive host files or credentials. Inspect cloned trees for symlinked, hardlinked, or special (`result.json`/`results.json`) entries before allowing the artifact-refresh step to run.","aliases":["GHSA-qx2g-vpwq-466c"],"modified":"2026-10-02T03:47:49.656466993Z","published":"2026-10-01T15:38:09.062Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-22","CWE-59"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94620.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94620.json"},{"type":"FIX","url":"https://github.com/foundation50/classroom50/commit/79112f33932d1b5c398a8801d97a8813d52d55ce"},{"type":"ADVISORY","url":"https://github.com/foundation50/classroom50/security/advisories/GHSA-qx2g-vpwq-466c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-94620"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/foundation50/classroom50","events":[{"introduced":"0"},{"fixed":"42d5d7285946059bf374875764539127ac3c6599"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.11.0"}],"source":"AFFECTED_FIELD"}}],"versions":["cli-v1.11.0","web-v1.10.0","cli-v1.10.0","web-v1.9.0","cli-v1.9.0","web-v1.8.0","cli-v1.8.0","web-v1.7.0","cli-v1.7.0","web-v1.6.0","cli-v1.6.0","web-v1.5.0","cli-v1.5.0","web-v1.4.0","cli-v1.4.0","web-v1.3.0","cli-v1.3.0","web-v1.2.0","cli-v1.2.0","web-v1.1.0","cli-v1.1.0","web-v1.0.0","cli-v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94620.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}