CVE-2024-28189
Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacker can abuse this by creating a symbolic link (s...
Affects 0 products across 3 vendors.
Software follows symbolic links without verifying the target, allowing read, write, or delete of unintended files.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
CVE-2024-28189 affects Judge0, an open-source online code execution system, by allowing an attacker to manipulate file ownership outside the sandbox through a symbolic link.
BSID: BS-2024-GLOBAL-206350-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2024-28189?
What is the CVSS score for CVE-2024-28189?
Is CVE-2024-28189 actively exploited?
How do I remediate CVE-2024-28189?
What systems are affected by CVE-2024-28189?
| CVE ID | CVE-2024-28189 |
|---|---|
| BSID | BS-2024-GLOBAL-206350-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| Published | 2024-04-18 |
| Last Modified | 2026-04-15 |
| ICS Relevance | 15% |
| Weakness (CWE) | |
| Source | NVD |
Judge0 is an open-source online code execution system. The application uses the UNIX chown command on an untrusted file within the sandbox. An attacker can abuse this by creating a symbolic link (symlink) to a file outside the sandbox, allowing the attacker to run chown on arbitrary files outside of the sandbox. This vulnerability is not impactful on it's own, but it can be used to bypass the patch for CVE-2024-28185 and obtain a complete sandbox escape. This vulnerability is fixed in 1.13.1.
Source: NIST NVD / MITRE CVE Database
An attacker can create a symbolic link to a file outside the sandbox environment. By doing so, they can execute the UNIX chown command on this file, potentially leading to unauthorized file ownership changes and bypassing intended security measures.
Exploitation Likelihood: MEDIUM
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
SAGE Enrichment Record — provenance & audit hash
| Model | /workspace/models/qwen2.5-coder-32b-instruct-bf16 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 31eba744f130d5be0e76cc77bb4b8e0d239d10a93bce8196a79f0f00e695c56a07f80eee00193adc0a2504aa6463750487a574e892e7113e51c3db00c6e943f4 |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →