PT-2026-38443 · Inducer · Relate

Published

2026-05-07

·

Updated

2026-05-07

·

CVE-2026-41505

CVSS v3.1

8.7

High

VectorAV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:H
RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make sign in key() function and exam.py's gen ticket code() function. This issue has been patched via commit 2f68e16.

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

CVE-2026-41505

Affected Products

Relate