{"id":"GHSA-6p4f-j8j6-463q","summary":"Indico: Missing access check in legacy session export API","details":"### Impact\nA legacy API to retrieve session details could be misused to retrieve metadata (such as title, description and conveners) of a restricted session within without having access to that session, as long as the event itself was accessible.\n\n### Patches\nYou should to update to [Indico 3.3.13](https://github.com/indico/indico/releases/tag/v3.3.13) as soon as possible.\nSee [the docs](https://docs.getindico.io/en/stable/installation/upgrade/) for instructions on how to update.\n\n### Workarounds\nRestrict access to the event itself\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n- Open a thread in [our forum](https://talk.getindico.io/)\n- Email us privately at [indico-team@cern.ch](mailto:indico-team@cern.ch)","aliases":["CVE-2026-107395"],"modified":"2026-10-08T22:30:19.551099366Z","published":"2026-10-08T22:09:49Z","database_specific":{"github_reviewed_at":"2026-10-08T22:09:49Z","nvd_published_at":"2026-10-08T20:17:34Z","cwe_ids":["CWE-862"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/indico/indico/security/advisories/GHSA-6p4f-j8j6-463q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107395"},{"type":"WEB","url":"https://github.com/indico/indico/commit/524e8e93eadcd8484905b1147020a35f5dce6038"},{"type":"PACKAGE","url":"https://github.com/indico/indico"},{"type":"WEB","url":"https://github.com/indico/indico/releases/tag/v3.3.13"}],"affected":[{"package":{"name":"indico","ecosystem":"PyPI","purl":"pkg:pypi/indico"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.13"}]}],"versions":["0.98-rc1","0.98.0","0.98.1","0.98.2","0.99","1.0","1.1","1.1.1","1.1.2","1.2","1.2.1","1.2.1rc10","1.2.1rc11","1.2.1rc2","1.2.1rc4","1.2.1rc5","1.2.1rc6","1.2.1rc7","1.2.1rc9","1.2.2","1.2.2rc1","1.9.11.dev10","1.9.11.dev11","1.9.11.dev12","1.9.11.dev13","1.9.11.dev14","1.9.11.dev15","1.9.11.dev16","1.9.11.dev17","1.9.11.dev3","1.9.11.dev4","1.9.11.dev6","1.9.11.dev7","1.9.11.dev8","1.9.11.dev9","2.0","2.0.1","2.0.2","2.0.3","2.0a1","2.0rc1","2.0rc2","2.1","2.1.1","2.1.10","2.1.11","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","2.2","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.3","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","3.0","3.0.1","3.0.2","3.0.3","3.0rc1","3.0rc2","3.1","3.1.1","3.2","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.2.8","3.2.9","3.3","3.3.1","3.3.10","3.3.11","3.3.12","3.3.2","3.3.3","3.3.4","3.3.5","3.3.6","3.3.7","3.3.8","3.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6p4f-j8j6-463q/GHSA-6p4f-j8j6-463q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"}]}