CVE-2026-107396: Indico: Cross-Site-Scripting in link fields
Impact There is a Cross-Site-Scripting vulnerability in fields that allow entering custom URLs.
Patches You should to update to Indico 3.3.13 as soon as possible. See the docs for instructions on how to update.
Workarounds - Set CSPENABLED = True in indico.conf - this is recommended regardless of updating. - Only let trustworthy users manage events or create content (including material uploads which speakers can typically do as well) on Indico.
For more information If you have any questions or comments about this advisory:
- Open a thread in our forum - Email us privately at indico-team@cern.ch
Other sources
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can manage events or create content, including speakers who can upload material, can store crafted javascript URLs in fields that accept custom URLs. A user who follows one of these URLs can execute attacker-controlled script in the user's browser in the Indico origin. This issue is fixed in version 3.3.13.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/indicoto a version that resolves this vulnerability.Fixed in 3.3.13 - Upgrade
Upgrade
Indicoto a version that resolves this vulnerability.Fixed in 3.3.13 - Configuration
Set CSP_ENABLED = True in indico.conf.
Indico CSP_ENABLED = True - Compensating control
Only allow trustworthy users to manage events or create content, including uploading material.
Event History
Frequently Asked Questions
Who can introduce malicious links?
Users who can manage events or create content can store crafted javascript URLs in custom URL fields. This includes speakers who are allowed to upload material.
What interaction is required for exploitation?
A user must follow a crafted URL stored in one of the affected custom URL fields. The resulting attacker-controlled script runs in that user's browser under the Indico origin.
Which versions should be remediated?
Indico versions prior to 3.3.13 are affected. Upgrade to version 3.3.13 to obtain the fix.