Disclosure summary
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can create content, including speakers who can create minutes, can store crafted HTML in event minutes. When concurrent edits are made to the same minutes, the minute editor conflict UI can execute attacker-controlled script in the viewer's browser in the Indico origin. This issue is fixed in version 3.3.13.
Source-reported weakness categories
CWE-79
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-cw24-x4mj-fw3q
Open original source · Updated Oct 08, 2026
Indico: Cross-Site-Scripting in minutes editor
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | indico | < 3.3.13 | 3.3.13 |
NIST National Vulnerability Database · NVD-CVE-2026-107397
Open original source · Updated Oct 08, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
Original records & references
PUBLISHED 2026-10-08T17:17:51-04:00
MODIFIED 2026-10-08T17:35:53-04:00
INGESTED 2026-10-10T20:55:03-04:00