GHSA-c4wc-ggrj-jg9v: Medium severity pip/indico vulnerability

Published Oct 8, 2026
·
Updated

Impact There is a Cross-Site-Scripting vulnerability in fields that allow entering custom URLs.

Patches You should to update to Indico 3.3.13 as soon as possible. See the docs for instructions on how to update.

Workarounds - Set CSPENABLED = True in indico.conf - this is recommended regardless of updating. - Only let trustworthy users manage events or create content (including material uploads which speakers can typically do as well) on Indico.

For more information If you have any questions or comments about this advisory:

- Open a thread in our forum - Email us privately at indico-team@cern.ch

Affected Software

1 affected componentFixes available
pip/indico<3.3.13
3.3.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/indico to a version that resolves this vulnerability.

    Fixed in 3.3.13
  2. Upgrade

    Upgrade Indico to a version that resolves this vulnerability.

    Fixed in 3.3.13
  3. Configuration

    Set CSP_ENABLED = True in indico.conf; this is recommended regardless of updating.

    Indico CSP_ENABLED = True
  4. Compensating control

    Only let trustworthy users manage events or create content, including material uploads, on Indico.

Event History

Oct 8, 2026
Advisory Published
via GitHub·10:09 PM
Data Sourced
via GitHub·10:09 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs permissions to enter custom URLs in Indico content fields. Users who can manage events, create content, or upload materials, including speakers where they are allowed to upload materials, may have relevant access.

2

What should be done to remediate the issue?

Update Indico to version 3.3.13 as soon as possible. Enable CSP by setting CSP_ENABLED = True in indico.conf; this is recommended even after updating.

3

What can reduce risk if an update cannot be applied immediately?

Enable CSP_ENABLED = True in indico.conf and restrict event-management, content-creation, and material-upload permissions to trustworthy users. This limits the users who can provide malicious custom URLs.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203