๐Ÿ” CVE Alert

CVE-2026-107394

MEDIUM 6.8

Indico: Incomplete Server-Side Request Forgery (SSRF) check

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to 3.3.13, the previous fix for CVE-2026-25738 did not cover an edge case, allowing an event organizer to submit a crafted URL that points to a prohibited local target but is accepted as valid by Indico. The organizer can read data returned by the target through affected Indico features. This issue is fixed in version 3.3.13.

CWE CWE-918
Vendor indico
Product indico
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for indico indico

Be the first to know when new medium vulnerabilities affecting indico indico are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

indico / indico
< 3.3.13

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/indico/indico/security/advisories/GHSA-2v95-h47v-g4x9 github.com: https://github.com/indico/indico/pull/7573 github.com: https://github.com/indico/indico/commit/44540e70ab4e20a12f14ddba5218a33749a86736 github.com: https://github.com/indico/indico/releases/tag/v3.3.13