Vulnerability GHSA-c4wc-ggrj-jg9v
Medium Risk
MEDIUM RISK
CVSS Score: 5.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
9 hours ago
October 08, 2026 at 10:09 PM UTC
Indico: Cross-Site-Scripting in link fields
0.98-rc1 - 3.3.12
0.98-rc1 - 3.3.12
Summary
Indico: Cross-Site-Scripting in link fields
Details
Impact
There is a Cross-Site-Scripting vulnerability in fields that allow entering custom URLs.
Patches
You should to update to Indico 3.3.13 as soon as possible. See the docs for instructions on how to update.
Workarounds
- Set
CSP_ENABLED = Trueinindico.conf- this is recommended regardless of updating. - Only let trustworthy users manage events or create content (including material uploads which speakers can typically do as well) on Indico.
For more information
If you have any questions or comments about this advisory:
- Open a thread in our forum
- Email us privately at [email protected]
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
9 hours ago
Indico: Missing access check in legacy session export API
0.98-rc1 - 3.3.12 GHSA-6p4f-j8j6-463q
0.98-rc1 - 3.3.12 GHSA-6p4f-j8j6-463q
Medium Risk
9 hours ago
Indico: Cross-Site-Scripting in minutes editor
0.98-rc1 - 3.3.12 GHSA-cw24-x4mj-fw3q
0.98-rc1 - 3.3.12 GHSA-cw24-x4mj-fw3q
Medium Risk
3 months ago
Indico may disclose unauthorized user details access via legacy API
0.98-rc1 - 3.3.7 PYSEC-2026-1460
0.98-rc1 - 3.3.7 PYSEC-2026-1460
Medium Risk
3 months ago
Indico vulnerable to Cross-Site Scripting via LaTeX math code
0.98-rc1 - 3.3.7 PYSEC-2026-1461
0.98-rc1 - 3.3.7 PYSEC-2026-1461
Unknown
3 months ago
Indico vulnerability allows attackers to bulk dump user details
2.2 - 3.3.6 PYSEC-2026-1462
2.2 - 3.3.6 PYSEC-2026-1462
Impacted packages
Timeline
Published
9 hours ago
October 08, 2026 at 10:09 PM UTC
Fixed (3.3.13)
1 month ago
August 25, 2026 at 02:00 PM UTC
Last Modified
8 hours ago
October 08, 2026 at 10:30 PM UTC