CVE-2026-107396: Stored Cross-Site Scripting (XSS) in Indico
Vulnerability ID: CVE-2026-107396
CVSS Score: 5.4
Published: 2026-10-08
A stored Cross-Site Scripting (XSS) vulnerability was identified in Indico, an open-source event management system developed at CERN, prior to version 3.3.13. The vulnerability stems from weak URL validation in custom link fields and lack of HTML sanitization during Marshmallow serialization of event notes. This allows authenticated attackers with event modification privileges to inject malicious payloads that execute in the browser of users viewing the event pages or collaborating on notes.
TL;DR
Stored XSS in Indico prior to 3.3.13 allows authenticated users to inject malicious URLs and scripts into custom links and event notes, executing in the context of victims' browsers.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-692
- Attack Vector: Network (AV:N)
- CVSS Score: 5.4 (Medium)
- EPSS Score: N/A
- Exploit Status: PoC (Proof of Concept)
- CISA KEV Status: Not Listed
Affected Systems
- Indico (event management system)
-
Indico: < 3.3.13 (Fixed in:
3.3.13)
Code Analysis
Commit: d4c8c71
Sanitize notes conflict resolution HTML and validate custom URLs to prevent stored XSS
Mitigation Strategies
- Upgrade Indico to version 3.3.13 or newer
- Implement a strong Content Security Policy (CSP) without 'unsafe-inline' in script-src
- Deploy Web Application Firewall (WAF) rules to filter 'javascript:' and 'onerror' strings in form payloads
Remediation Steps:
- Run 'pip install --upgrade indico>=3.3.13' to upgrade the installation.
- Verify the update by attempting to submit a 'javascript:' link in attachment forms; the platform should return a validation error.
- Audit existing custom links and event notes in the database for presence of 'javascript:' or 'onerror' payloads.
References
- GitHub Security Advisory GHSA-c4wc-ggrj-jg9v
- Official Fix Commit
- Pull Request #7619 (Sanitize Notes + Validate URLs)
- Indico v3.3.13 Release Notes
- CVE.org Authority Record
Read the full report for CVE-2026-107396 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)