{"id":"CVE-2026-25739","aliases":["GHSA-jxc4-54g3-j7vp","PYSEC-2026-2182"],"title":"Indico Affected by Cross-Site-Scripting via material uploads","summary":"Indico Affected by Cross-Site-Scripting via material uploads","severity":"medium","cvss":5.4,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N","vendor":"indico","product":"indico","ecosystem":"pip","affected":["indico < 3.3.10"],"patched":["indico 3.3.10"],"published":"2026-02-17","updated":"2026-07-13","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-jxc4-54g3-j7vp","references":[{"url":"https://github.com/indico/indico/security/advisories/GHSA-jxc4-54g3-j7vp"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-25739"},{"url":"https://github.com/indico/indico"},{"url":"https://github.com/indico/indico/releases/tag/v3.3.10"}],"tags":["osv","pip"],"epss":0.00167,"epssPercentile":0.06398,"ingestedAt":"2026-07-13T18:58:00.153Z","slug":"CVE-2026-25739","body":"## Overview\n\n### Impact\nThere is a Cross-Site-Scripting vulnerability when uploading certain file types as materials.\n\n### Patches\nYou should to update to [Indico 3.3.10](https://github.com/indico/indico/releases/tag/v3.3.10) as soon as possible.\nSee [the docs](https://docs.getindico.io/en/stable/installation/upgrade/) for instructions on how to update.\n\nPlease be aware that to apply the fix itself updating is sufficient, but to benefit from the strict Content-Security-Policy we now apply by default for file downloads, you need to update your webserver config in case you use nginx with Indico's `STATIC_FILE_METHOD` set to `xaccelredirect` and add the following line to the `.xsf/indico/` location block (you can consult the Indico setup documentation for the full configuration snippet):\n\n```nginx\nadd_header Content-Security-Policy $upstream_http_content_security_policy;\n```\n\n### Workarounds\n- Use your webserver config to apply a strict CSP for material download endpoints.\n- Only let trustworthy users create content (including material uploads, which speakers can typically do as well) on Indico.\n\n### For more information\nIf you have any questions or comments about this advisory:\n\n- Open a thread in [our forum](https://talk.getindico.io/)\n- Email us privately at [indico-team@cern.ch](mailto:indico-team@cern.ch)\n\n## Affected packages\n\n- `indico < 3.3.10`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `indico 3.3.10`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}