External risk intelligence

Classroom 50 Arbitrary File Write via Symlink Allows Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.4)

CVE-2026-94620

The vulnerability exists in a command-line utility used by teachers to download and manage student repositories locally. It is a client-side tool executed by a user on their own machine, not a public-facing service, network edge device, or internet-accessible application.

Path Traversal

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability exists in Classroom 50, an open-source tool for managing programming assignments, that could allow a student to overwrite critical system files or execute code on a teacher's computer. This occurs when the tool processes student repositories, as it incorrectly handles symbolic links within assignment files. While the tool has been updated to address this issue, a workaround involves avoiding the processing of untrusted student submissions or conducting the operation in an isolated environment.

  • Students could compromise teacher's systems.
  • Teacher's administrative access is at risk.
  • Confirm relevance and exposure of this tool.

Attack Path

How an attacker could exploit the issue

An attacker, acting as a student, could craft a malicious assignment repository containing a symlink disguised as an autograde artifact. When a teacher uses the `gh teacher download` command to retrieve assignments, this symlink could trick the tool into writing arbitrary data, such as malicious code, to sensitive files on the teacher's system. This could grant the attacker elevated privileges and control over the teacher's environment and organization.

  • Requires student control of assignment repository.
  • Triggered by teacher downloading assignments.
  • Risk of arbitrary file write and code execution.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability could allow a student to overwrite arbitrary files on a teacher's system by providing specially crafted symlinks within their assignment repository. When the teacher uses the `gh teacher download` command, these symlinks could redirect file writes to critical system files or SSH authorized keys, potentially leading to the execution of malicious code with the teacher's elevated privileges.

  • Teacher system files and credentials.
  • Writing through symlinks in student repos.
  • Arbitrary file write leading to code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Classroom 50 tool's `gh teacher download` command is vulnerable to arbitrary file writes, potentially leading to code execution as the teacher. This issue primarily impacts the application owner or the platform team responsible for managing and deploying Classroom 50, as well as security teams who oversee the integrity of teacher accounts and systems. The first practical step is to identify all instances of Classroom 50, assess their exposure, and confirm the responsible team for remediation.

  • Identify Classroom 50 instances.
  • Verify teacher account exposure.
  • Plan remediation and vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Classroom 50?

Classroom 50 is an open-source utility designed for computer science instructors to automate the management and grading of programming assignments hosted on GitHub. It connects with local environments to streamline the collection of student submissions. By integrating with the GitHub CLI, it helps educators process repositories and evaluate student work efficiently, though it requires interacting with files provided by students.

What does CVE-2026-94620 mean?

This CVE describes a security flaw involving Improper Neutralization of Special Elements used in an OS Command and improper handling of symbolic links, categorized as CWE-22 and CWE-59. Effectively, it means the software fails to recognize when a student has replaced a standard file with a link to a sensitive location. Consequently, the tool follows that link and writes data to a path outside the intended directory, enabling the creation or overwriting of files on the teacher's machine.

How is this vulnerability triggered?

An attacker triggers this by committing a symbolic link into their assignment repository instead of a regular autograde file. When an instructor runs the 'gh teacher download' command, the tool automatically processes these repositories. The vulnerability is not triggered if the repository lacks these specific malicious links, or if the tool is operated within a restricted environment where the user account lacks permissions to modify critical system files.

Is my Classroom 50 setup at risk?

According to Halo Surface Signal, risk is very unlikely because Classroom 50 is a local, client-side utility rather than an internet-facing service or network appliance. The vulnerability requires the teacher to manually download and process a repository containing the malicious link. The threat is confined to the local machine where the instructor performs these operations, rather than a broad network or server-side exposure.

How can I protect my system from this issue?

The primary resolution is to update to version 1.11.0, which includes a fix for symlink handling. If you cannot update immediately, avoid using the tool on untrusted student repositories. Alternatively, perform the download process within a disposable sandbox or container that has no access to sensitive host directories, user credentials, or SSH keys, thereby isolating any attempted writes from your actual system files.

References