Predictable Token Generation Vulnerability in RELATE by Inducer
CVE-2026-41505
8.7HIGH
What is CVE-2026-41505?
RELATE, a web-based courseware package developed by Inducer, is susceptible to predictable token generation. This vulnerability exists in the functions make_sign_in_key() in auth.py and gen_ticket_code() in exam.py, potentially allowing unauthorized access. A fix has been implemented in commit 2f68e16 to address this security issue.
Affected Version(s)
relate < 2f68e16cd3b96d25c188c1aa3f7e13cdb15cdaeb
