There is a Cross-Site-Scripting vulnerability in fields that allow entering custom URLs.
You should to update to Indico 3.3.13 as soon as possible. See the docs for instructions on how to update.
CSP_ENABLED = True in indico.conf - this is recommended regardless of updating.If you have any questions or comments about this advisory:
{
"cwe_ids": [
"CWE-692"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T22:09:41Z",
"nvd_published_at": "2026-10-08T20:17:34Z",
"severity": "MODERATE"
}