PT-2026-108191 · Indico · Indico
CVE-2026-107394
·
Published
2026-10-08
·
Updated
2026-10-08
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Indico versions prior to 3.3.13
Description
Indico allows event organizers to submit crafted URLs that bypass validation filters to point to prohibited local targets, such as localhost or cloud metadata endpoints. This occurs because a previous fix did not cover a specific edge case, enabling a Server-Side Request Forgery (SSRF) where the organizer can read data returned by the target through affected features.
Recommendations
Update to version 3.3.13.
Use the
http proxy and https proxy environment variables on the indico-uwsgi and indico-celery services to force outgoing requests through a proxy that limits access to sensitive targets.Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Indico