CVE-2026-25739: Indico affected by Cross-Site-Scripting via material uploads
Impact There is a Cross-Site-Scripting vulnerability when uploading certain file types as materials.
Patches You should to update to Indico 3.3.10 as soon as possible. See the docs for instructions on how to update.
Please be aware that to apply the fix itself updating is sufficient, but to benefit from the strict Content-Security-Policy we now apply by default for file downloads, you need to update your webserver config in case you use nginx with Indico's STATICFILEMETHOD set to xaccelredirect and add the following line to the .xsf/indico/ location block (you can consult the Indico setup documentation for the full configuration snippet):
nginx addheader Content-Security-Policy $upstreamhttpcontentsecuritypolicy;
Workarounds - Use your webserver config to apply a strict CSP for material download endpoints. - Only let trustworthy users create content (including material uploads, which speakers can typically do as well) on Indico.
For more information If you have any questions or comments about this advisory:
- Open a thread in our forum - Email us privately at indico-team@cern.ch
Other sources
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to cross-site scripting when uploading certain file types as materials. Users should upgrade to version 3.3.10 to receive a patch. To apply the fix itself updating is sufficient, but to benefit from the strict Content Security Policy (CSP) Indico now applies by default for file downloads, update the webserver config in case one uses nginx with Indico's STATICFILEMETHOD set to xaccelredirect. For further directions, consult the GitHub Security advisory or Indico setup documentation. Some workarounds are available. Use the webserver config to apply a strict CSP for material download endpoints, and/or only let trustworthy users create content (including material uploads, which speakers can typically do as well) on Indico.
— NVD
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25739?
CVE-2026-25739 has been classified as a medium severity Cross-Site Scripting vulnerability.
How do I fix CVE-2026-25739?
To fix CVE-2026-25739, update to Indico version 3.3.10 or later.
What types of file uploads are affected by CVE-2026-25739?
CVE-2026-25739 affects the uploading of certain file types which can trigger the Cross-Site Scripting vulnerability.
Is CVE-2026-25739 exploited in the wild?
As of now, there are no confirmed reports of CVE-2026-25739 being actively exploited in the wild.
What software versions are vulnerable to CVE-2026-25739?
Indico versions prior to 3.3.10 are vulnerable to CVE-2026-25739.