CVE-2026-47161

Source
https://cve.org/CVERecord?id=CVE-2026-47161
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47161.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47161
Aliases
  • GHSA-4mwh-mwv4-m252
Published
2026-05-27T18:31:55Z
Modified
2026-10-08T02:50:59Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
RELATE Vulnerable to Remote Code Execution (RCE) via Insecure Celery Pickle Deserialization
Details

RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'pickle' data. An attacker who can reach the message broker can execute arbitrary commands on the host server. Combined with missing network isolation in the code execution sandbox, this allows an authenticated student to achieve full Remote Code Execution (RCE) on the host system. Commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb fixes the issue.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-502"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47161.json"
}
References

Affected packages

Git / github.com/inducer/relate

Affected ranges

Type
GIT
Repo
https://github.com/inducer/relate
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47161.json"