Judge0’s Sandbox Escape Vulnerabilities Lead to Complete System Takeover

Published:

spot_img

Judge0 Critical Security Flaws: Sandbox Escape Vulnerabilities and Root Permissions Risks

In a recent report by Australian cybersecurity firm Tanto Security, it has been revealed that multiple critical security flaws have been identified in the Judge0 open-source online code execution system. These vulnerabilities could potentially allow an attacker to execute code on the target system.

The flaws, reported by Daniel Cooper in March 2024, include CVE-2024-28185, CVE-2024-28189, and CVE-2024-29021, with severity scores ranging from 9.1 to 10.0. These vulnerabilities stem from issues such as bypassing security measures and leaving the service vulnerable to Server-Side Request Forgery (SSRF) attacks.

One of the critical vulnerabilities, CVE-2024-28185, allows an attacker to write to arbitrary files and gain code execution outside of the sandbox. Another flaw, CVE-2024-28189, involves the potential misuse of symbolic links to run chown commands on arbitrary files outside of the sandbox.

The most serious vulnerability, CVE-2024-29021, allows an attacker to escape the sandbox via SSRF and obtain unsandboxed code execution as root on the target machine. This flaw could lead to complete control over the system, including the database, internal networks, and other applications running on the host.

The maintainers of Judge0 have addressed these vulnerabilities in version 1.13.1 released on April 18, 2024. Users are strongly advised to update to the latest version to mitigate any potential risks posed by these security flaws.

This development underscores the importance of regular security updates and maintenance to ensure the integrity and security of online systems. It also highlights the critical role of responsible disclosure in addressing and resolving vulnerabilities in a timely manner.

spot_img

Related articles

Recent articles

RondoDox Botnet Targets Critical React2Shell Vulnerability to Take Over IoT Devices and Web Servers

Jan 01, 2026Ravie LakshmananNetwork Security / Vulnerability Ongoing Campaign Targets IoT Devices via RondoDox Botnet Cybersecurity experts have unveiled new details surrounding a prolonged attack campaign...

Emirates 2025: 55.6 Million Passengers, New Aircraft, Starlink Launch, and 180,500 Flights Expected

Emirates Airlines: A Year of Growth and Innovation in 2025 Emirates Airlines, a prominent name in the global aviation industry, experienced remarkable growth in 2025....

ITR Not Processed by December 31, 2025? Key Risks and Essential Steps for Taxpayers

With December 31, 2025, fast approaching, countless taxpayers across India are keenly watching the status of their Income Tax Returns (ITRs) for the ongoing...

Shai-Hulud Supply Chain Attack Steals $8.5 Million from Trust Wallet Users

markdown In a significant cyberattack, Trust Wallet users experienced a loss of $8.5 million in cryptocurrency, attributed to the ongoing Shai-Hulud npm supply...