{"id":"GHSA-c4wc-ggrj-jg9v","summary":"Indico: Cross-Site-Scripting in link fields","details":"### Impact\nThere is a Cross-Site-Scripting vulnerability in fields that allow entering custom URLs.\n\n### Patches\nYou should to update to [Indico 3.3.13](https://github.com/indico/indico/releases/tag/v3.3.13) as soon as possible.\nSee [the docs](https://docs.getindico.io/en/stable/installation/upgrade/) for instructions on how to update.\n\n### Workarounds\n- Set `CSP_ENABLED = True` in `indico.conf` - **this is recommended regardless of updating**.\n- Only let trustworthy users manage events or create content (including material uploads which speakers can typically do as well) on Indico.\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n- Open a thread in [our forum](https://talk.getindico.io/)\n- Email us privately at [indico-team@cern.ch](mailto:indico-team@cern.ch)","aliases":["CVE-2026-107396"],"modified":"2026-10-08T22:30:19.956924286Z","published":"2026-10-08T22:09:41Z","database_specific":{"nvd_published_at":"2026-10-08T20:17:34Z","cwe_ids":["CWE-692"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-10-08T22:09:41Z"},"references":[{"type":"WEB","url":"https://github.com/indico/indico/security/advisories/GHSA-c4wc-ggrj-jg9v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-107396"},{"type":"WEB","url":"https://github.com/indico/indico/pull/7619"},{"type":"WEB","url":"https://github.com/indico/indico/commit/d4c8c7127176efa4cb53c64119ca8ee2b551be18"},{"type":"PACKAGE","url":"https://github.com/indico/indico"},{"type":"WEB","url":"https://github.com/indico/indico/releases/tag/v3.3.13"}],"affected":[{"package":{"name":"indico","ecosystem":"PyPI","purl":"pkg:pypi/indico"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.13"}]}],"versions":["0.98-rc1","0.98.0","0.98.1","0.98.2","0.99","1.0","1.1","1.1.1","1.1.2","1.2","1.2.1","1.2.1rc10","1.2.1rc11","1.2.1rc2","1.2.1rc4","1.2.1rc5","1.2.1rc6","1.2.1rc7","1.2.1rc9","1.2.2","1.2.2rc1","1.9.11.dev10","1.9.11.dev11","1.9.11.dev12","1.9.11.dev13","1.9.11.dev14","1.9.11.dev15","1.9.11.dev16","1.9.11.dev17","1.9.11.dev3","1.9.11.dev4","1.9.11.dev6","1.9.11.dev7","1.9.11.dev8","1.9.11.dev9","2.0","2.0.1","2.0.2","2.0.3","2.0a1","2.0rc1","2.0rc2","2.1","2.1.1","2.1.10","2.1.11","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","2.2","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.3","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","3.0","3.0.1","3.0.2","3.0.3","3.0rc1","3.0rc2","3.1","3.1.1","3.2","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.2.8","3.2.9","3.3","3.3.1","3.3.10","3.3.11","3.3.12","3.3.2","3.3.3","3.3.4","3.3.5","3.3.6","3.3.7","3.3.8","3.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-c4wc-ggrj-jg9v/GHSA-c4wc-ggrj-jg9v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}