CVE-2026-94620: Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)
Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, gh teacher download clones each student's assignment repository and then writes autograde artifacts (result.json and results.json) into the just-cloned working tree. The write followed symlinks, so a student who committed result.json or results.json as a symlink (materialized verbatim by git clone) could redirect the teacher's write to an arbitrary path — e.g. ~/.zshrc, ~/.ssh/authorizedkeys, a cron file, or an in-clone .git/hooks/ file that git subsequently executes. The written bytes are attacker-controlled (the student's uploaded release asset for result.json; student-chosen submit-tag names for results.json). This is an arbitrary file write leading to code execution as the teacher, whose gh token carries admin:org, repo, and workflow across the entire classroom organization. Version 1.11.0 contains a patch. Some workarounds are available. Avoid running gh teacher download against untrusted student repositories, or run it inside a disposable sandbox / container with no access to sensitive host files or credentials. Inspect cloned trees for symlinked, hardlinked, or special (result.json/results.json) entries before allowing the artifact-refresh step to run.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Classroom 50to a version that resolves this vulnerability.Fixed in 1.11.0 - Compensating control
Run gh teacher download only inside a disposable sandbox or container with no access to sensitive host files or credentials.
- Compensating control
Inspect cloned assignment trees for symlinked, hardlinked, or special result.json/results.json entries before allowing the artifact-refresh step to run.
Event History
Frequently Asked Questions
Who can exploit this issue?
A student who can commit content to an assignment repository that a teacher later processes with `gh teacher download` can exploit it. The student needs to place `result.json` or `results.json` in the repository as a symlink and control the corresponding artifact content or submit-tag name.
Are default teacher workflows affected?
The affected behavior occurs when `gh teacher download` clones student assignment repositories and writes autograde artifacts into their working trees. Any teacher running that command against repositories controlled by untrusted students is exposed prior to version 1.11.0.
What is the impact on a teacher workstation?
The symlink can redirect the artifact write to an arbitrary path accessible to the teacher account, including shell startup files, SSH authorized keys, cron files, or Git hooks. This can lead to code execution as the teacher and expose the broad organization permissions held by that teacher's `gh` token.
What can be done before upgrading?
Do not run `gh teacher download` against untrusted student repositories. If it must be run, use a disposable sandbox or container that has no access to sensitive host files or credentials.