Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-28189

44
FAUCET Score

CVE-2024-28189 is a critical vulnerability in Judge0, an open-source online code execution system, affecting versions prior to 1.13.1. It allows an attacker to bypass the sandbox by creating a symbolic link to an arbitrary file, enabling the chown command to be executed outside the sandbox. This vulnerability has a CVSS score of 10.0 (Critical) due to its network-based attack vector, low complexity, and high impact on confidentiality, integrity, and availability, potentially leading to a complete sandbox escape. While not directly impactful, it is crucial for bypassing the patch for CVE-2024-28185. Exploit code is publicly available via a Metasploit module, and it has garnered significant community discussion and media coverage, indicating active awareness and potential for exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
Judge0Judge0
<= 1.13.0CNA affected

CVSS Data

CVSS version used by this source: 3.1

10.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
7.21%
Probability of exploitation in next 30 days
EPSS Percentile
93.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Metasploit: Judge0 sandbox escape · Mar 4, 2024
This CVE's current EPSS score of 0.0721 is in the 89th percentile among its peer group of 36,835 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Remediation records are not available for this CVE.

References

github.com / judge0/judge0/blob/v1.13.0/app/jobs/isolate_job.rb
github.com / judge0/judge0/commit/f3b8547b3b67863e4ea0ded3adcb963add56addd
github.com / judge0/judge0/security/advisories/GHSA-3xpw-36v7-2cmg
github.com / judge0/judge0/security/advisories/GHSA-h9g2-45c8-89cf