Cross-Site Scripting Vulnerability in Indico Event Management System by Indico
CVE-2026-25739
What is CVE-2026-25739?
Indico, an event management system utilizing Flask-Multipass for multi-backend authentication, is susceptible to cross-site scripting (XSS) vulnerabilities when certain file types are uploaded as materials in versions earlier than 3.3.10. Users are urged to update to version 3.3.10 to mitigate the risk. While updating the software itself resolves the core issue, those utilizing nginx and the STATIC_FILE_METHOD set to xaccelredirect will need to adjust their webserver configurations to implement a strict Content Security Policy (CSP) for file downloads. For comprehensive instructions, refer to Indico's setup documentation or the GitHub Security advisory. Additionally, it is advisable to limit content creation rights to trusted users to further enhance security.
Affected Version(s)
indico < 3.3.10
