Cross-Site Scripting Vulnerability in Indico Event Management System by Indico
CVE-2026-25739

5.4MEDIUM

Key Information:

Vendor

Indico

Status
Vendor
CVE Published:
19 February 2026

What is CVE-2026-25739?

Indico, an event management system utilizing Flask-Multipass for multi-backend authentication, is susceptible to cross-site scripting (XSS) vulnerabilities when certain file types are uploaded as materials in versions earlier than 3.3.10. Users are urged to update to version 3.3.10 to mitigate the risk. While updating the software itself resolves the core issue, those utilizing nginx and the STATIC_FILE_METHOD set to xaccelredirect will need to adjust their webserver configurations to implement a strict Content Security Policy (CSP) for file downloads. For comprehensive instructions, refer to Indico's setup documentation or the GitHub Security advisory. Additionally, it is advisable to limit content creation rights to trusted users to further enhance security.

Affected Version(s)

indico < 3.3.10

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.