CVE-2026-33046: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-33046 is a LaTeX injection vulnerability in Indico (CERN's open-source event management system) that allows low-privileged authenticated users to read local files or execute arbitrary code on the server. It affects all Indico versions prior to 3.3.12 and is only exploitable when server-side LaTeX rendering is enabled (i.e., XELATEX_PATH is configured in indico.conf). The vulnerability was disclosed on March 23, 2026, via a GitHub Security Advisory. It carries a CVSS v3.1 base score of 8.8 (High) and a CVSS v4.0 base score of 7.7 (High) (GitHub Advisory).

Technical details

The root cause lies in insufficient sanitization of LaTeX input within Indico's mdx_latex.py module, classified as CWE-22 (Path Traversal) and CWE-78 (OS Command Injection). Indico's LaTeX sanitizer failed to account for obscure TeXLive and LaTeX caret-encoding syntax (e.g., ^^5c as an encoded backslash), which allowed attackers to smuggle dangerous LaTeX commands past the regex-based blocklist. Specifically, the sanitize_mathmode and latex_escape functions did not fully resolve multi-caret encoded sequences before applying safety checks, enabling injection of commands like \input{} for file reads or shell-escape primitives for code execution. The fix involved multiple iterative patches (commits 1dbb125, fb169ce, 0adb70f, 5f24d23) that progressively hardened the caret-resolution logic and tightened the allowlist of safe LaTeX environments and commands (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows a low-privileged Indico user to read arbitrary local files from the server (e.g., configuration files, credentials, private keys) or execute arbitrary OS commands with the privileges of the user running the Indico service (indico-uwsgi/indico-celery). This can result in complete server compromise, credential theft, lateral movement within the hosting environment, and exfiltration of sensitive event or user data managed by the platform. The scope is limited to the vulnerable system itself (no subsequent system impact in CVSS v4 terms), but the high confidentiality, integrity, and availability impact on the Indico server makes this a critical operational risk for affected deployments (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation as of the time of disclosure (GitHub Advisory). The vulnerability requires a low-privilege authenticated account on an Indico instance with server-side LaTeX rendering enabled, which limits the attack surface. The EPSS score is approximately 0.084%, reflecting a low current probability of exploitation. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was discovered by researchers credited as dreyercito and daw1012345 (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify an Indico instance (version < 3.3.12) with server-side LaTeX rendering enabled. This can be inferred if the instance generates PDF abstracts or proceedings using XeLaTeX.
  2. Obtain low-privilege access: Register or log in to the Indico instance with any valid user account (e.g., a free event registration account).
  3. Locate LaTeX input field: Navigate to a feature that accepts LaTeX input and triggers server-side rendering, such as abstract submission, contribution descriptions, or event descriptions that support math/LaTeX formatting.
  4. Craft malicious LaTeX payload: Construct a payload using caret-encoded syntax to bypass the sanitizer. For example, use ^^5c or multi-caret sequences to encode a backslash and inject commands like \input{/etc/passwd} (for file read) or leverage \write18{...} (shell escape, if enabled in TeXLive) for code execution.
  5. Submit and trigger rendering: Submit the crafted input and trigger PDF generation (e.g., by generating a book of abstracts or a contribution PDF).
  6. Retrieve output: The contents of the targeted local file or the result of the executed command may appear in the generated PDF or error output, depending on the LaTeX command used (GitHub Advisory).

Indicators of compromise

  • Logs: Indico application logs (indico-uwsgi or indico-celery) showing LaTeX rendering jobs submitted by unexpected or low-privilege users; XeLaTeX process logs (output.log) containing references to sensitive file paths (e.g., /etc/passwd, /etc/shadow, indico.conf) or shell command output.
  • File System: Unexpected temporary .tex source files in the Indico working/temp directory containing \input{}, \write18{}, or caret-encoded command sequences; newly created or modified files in the Indico installation directory owned by the service account.
  • Process: Unusual child processes spawned by the xelatex or indico-celery process (e.g., sh, bash, curl, wget, python) visible in process trees.
  • Network: Unexpected outbound network connections from the Indico server process to external IPs, potentially indicating a reverse shell or data exfiltration attempt following code execution.

Mitigation and workarounds

Update Indico to version 3.3.12 or later as soon as possible, which includes multiple iterative fixes to the LaTeX sanitizer regex logic (GitHub Advisory). As an immediate workaround for deployments that cannot upgrade, disable server-side LaTeX rendering by removing, commenting out, or setting XELATEX_PATH = None in indico.conf, then restarting the indico-uwsgi and indico-celery services. Additionally, the Indico team strongly recommends enabling the containerized LaTeX renderer using podman, which isolates the LaTeX process from the rest of the system and is now the only officially recommended/supported method for LaTeX rendering going forward.

Community reactions

The advisory was published by the Indico maintainer (ThiefMaster) on GitHub on March 23, 2026, crediting researchers dreyercito and daw1012345 for discovery. The vulnerability required multiple patch iterations (at least four commits) to fully address the obscure LaTeX caret-encoding bypass techniques, with the maintainer's commit message humorously noting "Fix LaTeX regexps (third time's the charm)" and "WTF LaTeX, WTF!", reflecting the complexity of the sanitization challenge (Patch Commit, Patch Commit). The vulnerability was picked up by standard CVE tracking feeds and INCIBE-CERT shortly after disclosure, but no major independent security research publications or broad social media discussion have been identified.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management