There is a Cross-Site-Scripting vulnerability in the minute editor conflict UI tha's shown when concurrent edits are made to the same minutes in an event.
You should to update to Indico 3.3.13 as soon as possible. See the docs for instructions on how to update.
CSP_ENABLED = True in indico.conf - this is recommended regardless of updating.If you have any questions or comments about this advisory:
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-10-08T22:09:45Z",
"nvd_published_at": "2026-10-08T21:17:51Z",
"severity": "MODERATE"
}