---
id: CVE-2026-107396
title: >-
  Indico is an event management system that uses Flask-Multipass, a
  multi-backend authentication system for Flask
summary: >-
  Indico is an event management system that uses Flask-Multipass, a
  multi-backend authentication system for Flask. Prior to 3.3.13, users who can
  manage events or create content, including speakers who can upload material,
  can store crafte…
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-692
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T20:48:36.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107396'
references:
  - url: >-
      https://github.com/indico/indico/commit/d4c8c7127176efa4cb53c64119ca8ee2b551be18
    label: security-advisories@github.com
  - url: 'https://github.com/indico/indico/pull/7619'
    label: security-advisories@github.com
  - url: 'https://github.com/indico/indico/releases/tag/v3.3.13'
    label: security-advisories@github.com
  - url: 'https://github.com/indico/indico/security/advisories/GHSA-c4wc-ggrj-jg9v'
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107396'
  - url: 'https://github.com/advisories/GHSA-c4wc-ggrj-jg9v'
  - url: 'https://github.com/indico/indico'
tags:
  - nvd
  - ghsa
  - pip
  - osv
ingestedAt: '2026-10-08T21:07:56.434Z'
aliases:
  - GHSA-c4wc-ggrj-jg9v
ecosystem: pip
vendor: indico
product: indico
affected:
  - indico < 3.3.13
patched:
  - indico 3.3.13
---

## Overview

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can manage events or create content, including speakers who can upload material, can store crafted javascript URLs in fields that accept custom URLs. A user who follows one of these URLs can execute attacker-controlled script in the user's browser in the Indico origin. This issue is fixed in version 3.3.13.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107396)

Affected packages:

- `indico < 3.3.13`

Patched in:

- `indico 3.3.13`

Source: https://github.com/advisories/GHSA-c4wc-ggrj-jg9v
