PT-2026-108191 · Indico · Indico

CVE-2026-107394

·

Published

2026-10-08

·

Updated

2026-10-08

CVSS v3.1

6.8

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Indico versions prior to 3.3.13
Description Indico allows event organizers to submit crafted URLs that bypass validation filters to point to prohibited local targets, such as localhost or cloud metadata endpoints. This occurs because a previous fix did not cover a specific edge case, enabling a Server-Side Request Forgery (SSRF) where the organizer can read data returned by the target through affected features.
Recommendations Update to version 3.3.13. Use the http proxy and https proxy environment variables on the indico-uwsgi and indico-celery services to force outgoing requests through a proxy that limits access to sensitive targets.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-107394
GHSA-2V95-H47V-G4X9

Affected Products

Indico