{"id":"GHSA-rm2q-f7jv-3cfp","summary":"Indico discloses local files resulting in Remote Code Execution through LaTeX injection ","details":"\u003e [!NOTE]\n\u003e If server-side LaTeX rendering is not in use (ie `XELATEX_PATH` was not set in `indico.conf`), this vulnerability does not apply.\n\n### Impact\nDue to vulnerabilities in TeXLive and obscure LaTeX syntax that allowed circumventing Indico's LaTeX sanitizer, it is possible to use specially-crafted LaTeX snippets which can read local files or execute code with the privileges of the user running Indico on the server.\n\n### Patches\nIt is recommended to update to [Indico 3.3.12](https://github.com/indico/indico/releases/tag/v3.3.12) as soon as possible.\nSee [the docs](https://docs.getindico.io/en/stable/installation/upgrade/) for instructions on how to update.\n\nIt is also strongly recommended to enable the containerized LaTeX renderer (using `podman`), which isolates it from the rest of the system. See [the docs](https://docs.getindico.io/en/stable/installation/upgrade/#upgrading-to-3-3-12) for details - it is very easy and from now on the only recommended/supported way of using LaTeX.\n\n### Workarounds\nRemove the `XELATEX_PATH` setting from `indico.conf` (or comment it out or set it to `None`) and restart the `indico-uwsgi` and `indico-celery` services to disable LaTeX functionality.\n\n### For more information\nFor any questions or comments about this advisory:\n\n- Open a thread in [the forum](https://talk.getindico.io/)\n- Send an email to [indico-team@cern.ch](mailto:indico-team@cern.ch)","aliases":["CVE-2026-33046","PYSEC-2026-2184"],"modified":"2026-07-13T07:26:43.762604006Z","published":"2026-03-23T20:43:43Z","database_specific":{"github_reviewed_at":"2026-03-23T20:43:43Z","nvd_published_at":"2026-03-23T23:17:12Z","cwe_ids":["CWE-22","CWE-78"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/indico/indico/security/advisories/GHSA-rm2q-f7jv-3cfp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-33046"},{"type":"WEB","url":"https://github.com/indico/indico/commit/0adb70f0ed66e129361d447868f5f3eb90dc5e96"},{"type":"WEB","url":"https://github.com/indico/indico/commit/1dbb12525b3de14229bf4d1ae192988068f975f6"},{"type":"WEB","url":"https://github.com/indico/indico/commit/5f24d23ce9c4b0e4b68b3d0b58987a948fc57c8a"},{"type":"WEB","url":"https://github.com/indico/indico/commit/fb169ced710c30cf792ce4b9f48688db0633cfd8"},{"type":"PACKAGE","url":"https://github.com/indico/indico"},{"type":"WEB","url":"https://github.com/indico/indico/releases/tag/v3.3.12"}],"affected":[{"package":{"name":"indico","ecosystem":"PyPI","purl":"pkg:pypi/indico"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.3.12"}]}],"versions":["0.98-rc1","0.98.0","0.98.1","0.98.2","0.99","1.0","1.1","1.1.1","1.1.2","1.2","1.2.1","1.2.1rc10","1.2.1rc11","1.2.1rc2","1.2.1rc4","1.2.1rc5","1.2.1rc6","1.2.1rc7","1.2.1rc9","1.2.2","1.2.2rc1","1.9.11.dev10","1.9.11.dev11","1.9.11.dev12","1.9.11.dev13","1.9.11.dev14","1.9.11.dev15","1.9.11.dev16","1.9.11.dev17","1.9.11.dev3","1.9.11.dev4","1.9.11.dev6","1.9.11.dev7","1.9.11.dev8","1.9.11.dev9","2.0","2.0.1","2.0.2","2.0.3","2.0a1","2.0rc1","2.0rc2","2.1","2.1.1","2.1.10","2.1.11","2.1.2","2.1.3","2.1.4","2.1.5","2.1.6","2.1.7","2.1.8","2.1.9","2.2","2.2.1","2.2.2","2.2.3","2.2.4","2.2.5","2.2.6","2.2.7","2.2.8","2.3","2.3.1","2.3.2","2.3.3","2.3.4","2.3.5","3.0","3.0.1","3.0.2","3.0.3","3.0rc1","3.0rc2","3.1","3.1.1","3.2","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.2.8","3.2.9","3.3","3.3.1","3.3.10","3.3.11","3.3.2","3.3.3","3.3.4","3.3.5","3.3.6","3.3.7","3.3.8","3.3.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-rm2q-f7jv-3cfp/GHSA-rm2q-f7jv-3cfp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}