Disclosure summary
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can manage events or create content, including speakers who can upload material, can store crafted javascript URLs in fields that accept custom URLs. A user who follows one of these URLs can execute attacker-controlled script in the user's browser in the Indico origin. This issue is fixed in version 3.3.13.
Source-reported weakness categories
CWE-692
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2026-107396
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
GitHub Reviewed Security Advisories · GHSA-c4wc-ggrj-jg9v
Open original source · Updated Oct 08, 2026
Indico: Cross-Site-Scripting in link fields
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | indico | < 3.3.13 | 3.3.13 |
Original records & references
PUBLISHED 2026-10-08T16:17:34-04:00
MODIFIED 2026-10-09T12:17:23-04:00
INGESTED 2026-10-10T20:55:03-04:00