All 4 CVE vulnerabilities found in relate, with AI-generated Chinese analysis, references, and POCs.
Vendor: inducer
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-47161 | RELATE Vulnerable to Remote Code Execution (RCE) via Insecure Celery Pickle Deserialization CWE-502 | - | - | 2026-05-27 |
| CVE-2026-42197 | RELATE Vulnerable to Stored XSS via Unprivileged User Profile CWE-79 | 8.7 | High | 2026-05-27 |
| CVE-2026-41588 | RELATE: Timing Attack Vulnerability in course/auth.py — check_sign_in_key() CWE-208 | 9.0 | Critical | 2026-05-08 |
| CVE-2026-41505 | RELATE: Predictable Token Generation in auth.py and exam.py CWE-338 | 8.7 | High | 2026-05-07 |
All 4 known CVE vulnerabilities affecting relate with full Chinese analysis, references, and POCs where available.