CVE-2026-25739: Indico affected by Cross-Site-Scripting via material uploads

Published Feb 17, 2026
·
Updated

Impact There is a Cross-Site-Scripting vulnerability when uploading certain file types as materials.

Patches You should to update to Indico 3.3.10 as soon as possible. See the docs for instructions on how to update.

Please be aware that to apply the fix itself updating is sufficient, but to benefit from the strict Content-Security-Policy we now apply by default for file downloads, you need to update your webserver config in case you use nginx with Indico's STATICFILEMETHOD set to xaccelredirect and add the following line to the .xsf/indico/ location block (you can consult the Indico setup documentation for the full configuration snippet):

nginx addheader Content-Security-Policy $upstreamhttpcontentsecuritypolicy;

Workarounds - Use your webserver config to apply a strict CSP for material download endpoints. - Only let trustworthy users create content (including material uploads, which speakers can typically do as well) on Indico.

For more information If you have any questions or comments about this advisory:

- Open a thread in our forum - Email us privately at indico-team@cern.ch

Other sources

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Versions prior to 3.3.10 are vulnerable to cross-site scripting when uploading certain file types as materials. Users should upgrade to version 3.3.10 to receive a patch. To apply the fix itself updating is sufficient, but to benefit from the strict Content Security Policy (CSP) Indico now applies by default for file downloads, update the webserver config in case one uses nginx with Indico's STATICFILEMETHOD set to xaccelredirect. For further directions, consult the GitHub Security advisory or Indico setup documentation. Some workarounds are available. Use the webserver config to apply a strict CSP for material download endpoints, and/or only let trustworthy users create content (including material uploads, which speakers can typically do as well) on Indico.

— NVD

Affected Software

2 affected componentsFixes available
pip/indico<3.3.10
3.3.10
cern Indico<3.3.10

Event History

Feb 17, 2026
Advisory Published
via GitHub·06:54 PM
Data Sourced
via GitHub·06:54 PM
DescriptionSeverityWeaknessAffected Software
Feb 19, 2026
CVE Published
via MITRE·03:39 PM
Data Sourced
via MITRE·03:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:27 PM
RemedyAffected Software
Jan 23, 58126
Event
via FIRST·10:16 PM

Frequently Asked Questions

1

What is the severity of CVE-2026-25739?

CVE-2026-25739 has been classified as a medium severity Cross-Site Scripting vulnerability.

2

How do I fix CVE-2026-25739?

To fix CVE-2026-25739, update to Indico version 3.3.10 or later.

3

What types of file uploads are affected by CVE-2026-25739?

CVE-2026-25739 affects the uploading of certain file types which can trigger the Cross-Site Scripting vulnerability.

4

Is CVE-2026-25739 exploited in the wild?

As of now, there are no confirmed reports of CVE-2026-25739 being actively exploited in the wild.

5

What software versions are vulnerable to CVE-2026-25739?

Indico versions prior to 3.3.10 are vulnerable to CVE-2026-25739.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203