CVE-2026-107396

medium

Description

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can manage events or create content, including speakers who can upload material, can store crafted javascript URLs in fields that accept custom URLs. A user who follows one of these URLs can execute attacker-controlled script in the user's browser in the Indico origin. This issue is fixed in version 3.3.13.

References

https://github.com/indico/indico/security/advisories/GHSA-c4wc-ggrj-jg9v

https://github.com/indico/indico/releases/tag/v3.3.13

https://github.com/indico/indico/pull/7619

https://github.com/indico/indico/commit/d4c8c7127176efa4cb53c64119ca8ee2b551be18

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-95214

Details

Source: Mitre, NVD

Published: 2026-10-08

Updated: 2026-10-09

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00195