CVE-2024-28189

CRITICAL

Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacker can abuse this by creating a symbolic link (s...

Affects 0 products across 3 vendors.

BCS7.96
CVSS 3.110.0
EPSS7.2%
Percentile94th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, can impact systems beyond the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-59: Improper Link Resolution Before File Access

Software follows symbolic links without verifying the target, allowing read, write, or delete of unintended files.

CWE-61: CWE-61
Related Attack Patterns (CAPEC)
CAPEC-27 Leveraging Race Conditions via Symbolic Links
via CWE-61
CAPEC-35 Leverage Executable Code in Non-Executable Files
via CWE-59
CAPEC-76 Manipulating Web Input to File System Calls
via CWE-59
CAPEC-132 Symlink Attack
via CWE-59
CAPEC-17 Using Malicious Files
via CWE-59

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

CVE-2024-28189 affects Judge0, an open-source online code execution system, by allowing an attacker to manipulate file ownership outside the sandbox through a symbolic link.

BSID: BS-2024-GLOBAL-206350-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2024-28189?
CVE-2024-28189 affects Judge0, an open-source online code execution system, by allowing an attacker to manipulate file ownership outside the sandbox through a symbolic link.
What is the CVSS score for CVE-2024-28189?
CVE-2024-28189 has CVSS 10.0 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. EPSS: 7.2%.
Is CVE-2024-28189 actively exploited?
No confirmed active exploitation of CVE-2024-28189 as of 2026-05-30.
How do I remediate CVE-2024-28189?
Priority: HIGH.
What systems are affected by CVE-2024-28189?
CVE-2024-28189 affects: Abuse, Files, Sandbox.
Vulnerability Details
CVE IDCVE-2024-28189
BSIDBS-2024-GLOBAL-206350-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Published2024-04-18
Last Modified2026-04-15
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacker can abuse this by creating a symbolic link (symlink) to a file outside the sandbox, allowing the attacker to run chown on arbitrary files outside of the sandbox. This vulnerability is not impactful on it's own, but it can be used to bypass the patch for CVE-2024-28185 and obtain a complete sandbox escape. This vulnerability is fixed in 1.13.1.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can create a symbolic link to a file outside the sandbox environment. By doing so, they can execute the UNIX chown command on this file, potentially leading to unauthorized file ownership changes and bypassing intended security measures.

Exploitation Likelihood: MEDIUM

Affected Products
VendorProductFixed Version
Abuse —
Files —
Sandbox —
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 840 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceMEDIUM
Enriched At2026-05-24
SHA-512 Audit Hash31eba744f130d5be0e76cc77bb4b8e0d239d10a93bce8196a79f0f00e695c56a07f80eee00193adc0a2504aa6463750487a574e892e7113e51c3db00c6e943f4
Related CVEs affecting Abuse
CVE-2025-4378 10.0 Cleartext Transmission of Sensitive Information, Use of Hard-coded Credential... CVE-1999-0512 10.0 A mail server is explicitly configured to allow SMTP mail relay, which allows... CVE-2026-23693 10.0 ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elemen... CVE-2026-40089 9.9 Sonicverse is a Self-hosted Docker Compose stack for live radio streaming. Th... CVE-2026-27389 9.8 Authentication Bypass Using an Alternate Path or Channel vulnerability in des...
View all Abuse CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →