Vulnerability GHSA-6p4f-j8j6-463q
Medium Risk
MEDIUM RISK
CVSS Score: 4.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
15 hours ago
October 08, 2026 at 10:09 PM UTC
Indico: Missing access check in legacy session export API
0.98-rc1 - 3.3.12
0.98-rc1 - 3.3.12
Summary
Indico: Missing access check in legacy session export API
Details
Impact
A legacy API to retrieve session details could be misused to retrieve metadata (such as title, description and conveners) of a restricted session within without having access to that session, as long as the event itself was accessible.
Patches
You should to update to Indico 3.3.13 as soon as possible. See the docs for instructions on how to update.
Workarounds
Restrict access to the event itself
For more information
If you have any questions or comments about this advisory:
- Open a thread in our forum
- Email us privately at [email protected]
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
15 hours ago
Indico: Cross-Site-Scripting in minutes editor
0.98-rc1 - 3.3.12 GHSA-cw24-x4mj-fw3q
0.98-rc1 - 3.3.12 GHSA-cw24-x4mj-fw3q
Medium Risk
15 hours ago
Indico: Cross-Site-Scripting in link fields
0.98-rc1 - 3.3.12 GHSA-c4wc-ggrj-jg9v
0.98-rc1 - 3.3.12 GHSA-c4wc-ggrj-jg9v
Medium Risk
3 months ago
Indico may disclose unauthorized user details access via legacy API
0.98-rc1 - 3.3.7 PYSEC-2026-1460
0.98-rc1 - 3.3.7 PYSEC-2026-1460
Medium Risk
3 months ago
Indico vulnerable to Cross-Site Scripting via LaTeX math code
0.98-rc1 - 3.3.7 PYSEC-2026-1461
0.98-rc1 - 3.3.7 PYSEC-2026-1461
Unknown
3 months ago
Indico vulnerability allows attackers to bulk dump user details
2.2 - 3.3.6 PYSEC-2026-1462
2.2 - 3.3.6 PYSEC-2026-1462
Impacted packages
Timeline
Published
15 hours ago
October 08, 2026 at 10:09 PM UTC
Fixed (3.3.13)
1 month ago
August 25, 2026 at 02:00 PM UTC
Last Modified
15 hours ago
October 08, 2026 at 10:30 PM UTC