DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

CVE-2026-107396: CVE-2026-107396: Stored Cross-Site Scripting (XSS) in Indico

CVE-2026-107396: Stored Cross-Site Scripting (XSS) in Indico

Vulnerability ID: CVE-2026-107396
CVSS Score: 5.4
Published: 2026-10-08

A stored Cross-Site Scripting (XSS) vulnerability was identified in Indico, an open-source event management system developed at CERN, prior to version 3.3.13. The vulnerability stems from weak URL validation in custom link fields and lack of HTML sanitization during Marshmallow serialization of event notes. This allows authenticated attackers with event modification privileges to inject malicious payloads that execute in the browser of users viewing the event pages or collaborating on notes.

TL;DR

Stored XSS in Indico prior to 3.3.13 allows authenticated users to inject malicious URLs and scripts into custom links and event notes, executing in the context of victims' browsers.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-692
  • Attack Vector: Network (AV:N)
  • CVSS Score: 5.4 (Medium)
  • EPSS Score: N/A
  • Exploit Status: PoC (Proof of Concept)
  • CISA KEV Status: Not Listed

Affected Systems

  • Indico (event management system)
  • Indico: < 3.3.13 (Fixed in: 3.3.13)

Code Analysis

Commit: d4c8c71

Sanitize notes conflict resolution HTML and validate custom URLs to prevent stored XSS

Mitigation Strategies

  • Upgrade Indico to version 3.3.13 or newer
  • Implement a strong Content Security Policy (CSP) without 'unsafe-inline' in script-src
  • Deploy Web Application Firewall (WAF) rules to filter 'javascript:' and 'onerror' strings in form payloads

Remediation Steps:

  1. Run 'pip install --upgrade indico>=3.3.13' to upgrade the installation.
  2. Verify the update by attempting to submit a 'javascript:' link in attachment forms; the platform should return a validation error.
  3. Audit existing custom links and event notes in the database for presence of 'javascript:' or 'onerror' payloads.

References


Read the full report for CVE-2026-107396 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)