CVE-2026-107396 — Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask.
Description
Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can manage events or create content, including speakers who can upload material, can store crafted javascript URLs in fields that accept custom URLs. A user who follows one of these URLs can execute attacker-controlled script in the user's browser in the Indico origin. This issue is fixed in version 3.3.13.
CVSS v3.1 base metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NMedium severity
Band computed from the CVSS base score, not the source's own label — so it means the same thing across every feed.
AV
Network
Attack Vector
AC
Low
Attack Complexity
PR
Low
Privileges Required
UI
Required
User Interaction
S
Changed
Scope
C
Low
Confidentiality
I
Low
Integrity
A
None
Availability
References
- advisory[email protected]https://github.com/indico/indico/commit/d4c8c7127176efa4cb53c64119ca8ee2b551be18
- advisory[email protected]https://github.com/indico/indico/pull/7619
- advisory[email protected]https://github.com/indico/indico/releases/tag/v3.3.13
- advisory[email protected]https://github.com/indico/indico/security/advisories/GHSA-c4wc-ggrj-jg9v
Related threats
same CWE or vendorCVE-2026-71478 — league/commonmark is a PHP library for parsing and rendering CommonMark Markdown.
CVE-2026-71478 · 2mo ago
CVE-2024-42214 — HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server.
CVE-2024-42214 · 3mo ago
CVE-2024-23569 — HCL Aftermarket EPC is vulnerable to attack since the server is not configured with “X-XSS-Protection" header
CVE-2024-23569 · 3mo ago
CVE-2025-20240 — A vulnerability in the Web Authentication feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to conduct a reflected c…
CVE-2025-20240 · 1y ago