logo

Sandbox Escape Vulnerabilities in Judge0 Expose Systems to Complete Takeover

ID: 305d5f04-9457-58e0-8f80-93e4ac862a66

STIX ID: report--305d5f04-9457-58e0-8f80-93e4ac862a66

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-04-29

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Multiple critical vulnerabilities were disclosed in the Judge0 open-source code execution system (CVE-2024-28185, CVE-2024-28189, CVE-2024-29021) that enable sandbox escapes via symlink abuse and SSRF, potentially allowing unsandboxed root code execution, host filesystem access through privileged Docker configuration, and weaponization against the internal PostgreSQL database; maintainers released fixes in version 1.13.1 and users are advised to upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.