GHSA-cw24-x4mj-fw3q: XSS

Published Oct 8, 2026
·
Updated

Impact There is a Cross-Site-Scripting vulnerability in the minute editor conflict UI tha's shown when concurrent edits are made to the same minutes in an event.

Patches You should to update to Indico 3.3.13 as soon as possible. See the docs for instructions on how to update.

Workarounds - Set CSPENABLED = True in indico.conf - this is recommended regardless of updating. - Only let trustworthy users create content (including minutes which speakers can typically do as well) on Indico.

For more information If you have any questions or comments about this advisory:

- Open a thread in our forum - Email us privately at indico-team@cern.ch

Affected Software

1 affected componentFixes available
pip/indico<3.3.13
3.3.13

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade pip/indico to a version that resolves this vulnerability.

    Fixed in 3.3.13
  2. Upgrade

    Upgrade Indico to a version that resolves this vulnerability.

    Fixed in 3.3.13
  3. Configuration

    Set CSP_ENABLED = True in indico.conf.

    Indico CSP_ENABLED = True
  4. Compensating control

    Only let trustworthy users create content in Indico, including minutes that speakers can typically edit.

Event History

Oct 8, 2026
Advisory Published
via GitHub·10:09 PM
Data Sourced
via GitHub·10:09 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Who can exploit this issue?

Exploitation requires a user who can create content in Indico, including minutes. Speakers can typically create minutes, so access should be limited to trustworthy users.

2

When is the vulnerable interface exposed?

The issue is in the minute editor conflict UI, which is shown when concurrent edits are made to the same minutes in an event. An attacker would need to trigger or participate in that concurrent-edit scenario and induce a victim to interact with the affected UI.

3

What should be done if upgrading cannot happen immediately?

Set CSP_ENABLED = True in indico.conf and restrict content-creation permissions to trusted users. The advisory recommends enabling CSP regardless of whether the software is updated.

4

What version should be deployed to remediate the issue?

Update Indico to version 3.3.13 as soon as possible.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203