---
id: CVE-2026-107397
title: >-
  Indico is an event management system that uses Flask-Multipass, a
  multi-backend authentication system for Flask
summary: >-
  Indico is an event management system that uses Flask-Multipass, a
  multi-backend authentication system for Flask. Prior to 3.3.13, users who can
  create content, including speakers who can create minutes, can store crafted
  HTML in event mi…
severity: medium
cvss: 4.4
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: indico
product: indico
affected:
  - indico < 3.3.13
patched:
  - indico 3.3.13
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:35:53.890'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107397'
references:
  - url: >-
      https://github.com/indico/indico/commit/d4c8c7127176efa4cb53c64119ca8ee2b551be18
    label: security-advisories@github.com
  - url: 'https://github.com/indico/indico/pull/7619'
    label: security-advisories@github.com
  - url: 'https://github.com/indico/indico/releases/tag/v3.3.13'
    label: security-advisories@github.com
  - url: 'https://github.com/indico/indico/security/advisories/GHSA-cw24-x4mj-fw3q'
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107397'
  - url: 'https://github.com/advisories/GHSA-cw24-x4mj-fw3q'
tags:
  - nvd
  - ghsa
  - pip
aliases:
  - GHSA-cw24-x4mj-fw3q
ecosystem: pip
ingestedAt: '2026-10-08T22:11:53.857Z'
---

## Overview

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, users who can create content, including speakers who can create minutes, can store crafted HTML in event minutes. When concurrent edits are made to the same minutes, the minute editor conflict UI can execute attacker-controlled script in the viewer's browser in the Indico origin. This issue is fixed in version 3.3.13.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-107397)

Affected packages:

- `indico < 3.3.13`

Patched in:

- `indico 3.3.13`

Source: https://github.com/advisories/GHSA-cw24-x4mj-fw3q
