Executive brief
RELATE is a web-based learning management system (LMS) used for hosting and managing online courses. A security flaw allows an authenticated student to bypass the system's code execution sandbox and run unauthorized commands on the underlying server. This could lead to a total system takeover, allowing an attacker to access student data, modify course content, or disrupt the entire service.
Technical details
The RELATE LMS is vulnerable to Remote Code Execution (RCE) due to a combination of two flaws. First, the Celery worker configuration explicitly allows the 'pickle' serialization format, which is inherently insecure when processing untrusted data. Second, the Docker-based sandbox used to evaluate student code (e.g., PythonCodeQuestion) lacks network isolation, allowing code running within the sandbox to communicate with the host's internal network services, such as the Redis or RabbitMQ message broker. An authenticated student can submit code that sends a crafted pickle payload directly to the message broker. When the Celery worker retrieves and deserializes this payload, it executes arbitrary system commands on the host server. This issue is fixed in version 2026.1 (commit d66ba56).
Affected products
- inducer RELATE < 2026.1
Timeline
- 2026-05-17: advisory: GitHub Security Advisory published
- 2026-05-27: disclosed: CVE-2026-47161 published
- 2026-05-27: patched: Fix committed to repository