Critical security vulnerabilities have been discovered in Judge0, an open-source online code execution system, which could allow remote code execution on the targeted system.

The three critical flaws allow a hacker with sufficient access to bypass sandbox security measures and gain administrator privileges on the host computer, Tanto Security , an Australian cybersecurity firm , said in a report published today
Read more: How do hackers abuse EDR security solutions?
Judge0 (pronounced “judge zero”) is presented by its creators as a reliable, flexible and open-source web-based code execution system, ideal for developing applications with web-based code execution needs, such as candidate assessment, distance learning, web-based code editors and development environments (IDEs).
According to its website, the service has a customer base of 23 users that includes companies like AlgoDaily, CodeChum, and PYnative, among others, and the project has been broken 412 times on GitHub to date.
The flaws discovered and reported by Daniel Cooper in March 2024 are described below –
CVE-2024-28185 (CVSS score: 10.0) – The application ignores symbolic links placed inside the sandbox folder, a vulnerability that a hacker to write to random files and achieve code execution outside the sandbox environment.
CVE-2024-28189 (CVSS score: 10,0) – A technical bypass for updating the code regarding CVE-2024-28185 is performed using the UNIX chown command on an untrusted file within a sandbox. This allows hackers to create a symbolic link to a file outside the sandbox, providing the ability to execute the chown command on any file outside the restricted environment, increasing the security risk.
CVE-2024-29021 (CVSS score: 9.1) – The default configuration of Judge0 makes the service vulnerable to sandbox escape attacks via Server-Side Request Forgery (SSRF). This gives attackers who have sufficient access to the Judge0 API the ability to execute code as root on the target system without testing environment restrictions.
The issue originates from a Ruby script named “isolate_job.rb”, which is used to create a sandbox environment. This script is also responsible for executing code and recording the results of this process.
See more: North Korean hackers are incorporating AI into their attacks
Specifically, this process involves creating a symbolic link inside the directory, before adapting a bash script to launch the program, depending on the selected language. This allows writing to any system file, without a testing environment.
A hacker could exploit this weakness to change scripts within the system, achieving code outside the sandbox environment and inside the Docker container that manages the submission process.
Additionally, the attacker will be able to extend their privileges beyond the Docker container environment, due to the use of the privileged operation defined in the docker-compose.yml file.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
“This tactic allows the attacker to integrate into the main Linux file system, enabling them to then create files – such as a malicious cron process – to secure access to the system,” according to Herman Došilović from Judge0.
“From this point, the hacker gains full access to the Judge0 system, making everything available from the database to internal networks, the Judge0 web server, as well as any other applications running on the central Linux host.”
CVE-2024-29021 concerns a specific setting that allows communication with Judge0's PostgreSQL database, which is accessible via the Docker internal network. This allows hackers to use SSRF to connect to the database, modify the data type on specific columns, and execute commands.

See also: Cisco discloses root escalation flaw in IMC
After the shortcomings were revealed, version 1.13.1, announced on April 18, 2024, offers solutions to these problems, so Judge0 users are advised to upgrade to the latest version.
Source: thehackernews
