CVE-2026-94620: Classroom 50 vulnerable to arbitrary file overwrite on the teacher's machine via symlink in a student repo (gh teacher download)

Published Oct 1, 2026
·
Updated

Classroom 50 is a free and open-source tool for managing and grading programming assignments via GitHub. Prior to version 1.11.0, gh teacher download clones each student's assignment repository and then writes autograde artifacts (result.json and results.json) into the just-cloned working tree. The write followed symlinks, so a student who committed result.json or results.json as a symlink (materialized verbatim by git clone) could redirect the teacher's write to an arbitrary path — e.g. ~/.zshrc, ~/.ssh/authorizedkeys, a cron file, or an in-clone .git/hooks/ file that git subsequently executes. The written bytes are attacker-controlled (the student's uploaded release asset for result.json; student-chosen submit-tag names for results.json). This is an arbitrary file write leading to code execution as the teacher, whose gh token carries admin:org, repo, and workflow across the entire classroom organization. Version 1.11.0 contains a patch. Some workarounds are available. Avoid running gh teacher download against untrusted student repositories, or run it inside a disposable sandbox / container with no access to sensitive host files or credentials. Inspect cloned trees for symlinked, hardlinked, or special (result.json/results.json) entries before allowing the artifact-refresh step to run.

Affected Software

1 affected component
GitHub Classroom 50<1.11.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Classroom 50 to a version that resolves this vulnerability.

    Fixed in 1.11.0
  2. Compensating control

    Run gh teacher download only inside a disposable sandbox or container with no access to sensitive host files or credentials.

  3. Compensating control

    Inspect cloned assignment trees for symlinked, hardlinked, or special result.json/results.json entries before allowing the artifact-refresh step to run.

Event History

Oct 1, 2026
CVE Published
via MITRE·03:38 PM
Data Sourced
via MITRE·03:38 PM
DescriptionWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

A student who can commit content to an assignment repository that a teacher later processes with `gh teacher download` can exploit it. The student needs to place `result.json` or `results.json` in the repository as a symlink and control the corresponding artifact content or submit-tag name.

2

Are default teacher workflows affected?

The affected behavior occurs when `gh teacher download` clones student assignment repositories and writes autograde artifacts into their working trees. Any teacher running that command against repositories controlled by untrusted students is exposed prior to version 1.11.0.

3

What is the impact on a teacher workstation?

The symlink can redirect the artifact write to an arbitrary path accessible to the teacher account, including shell startup files, SSH authorized keys, cron files, or Git hooks. This can lead to code execution as the teacher and expose the broad organization permissions held by that teacher's `gh` token.

4

What can be done before upgrading?

Do not run `gh teacher download` against untrusted student repositories. If it must be run, use a disposable sandbox or container that has no access to sensitive host files or credentials.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203