CVE-2025-59035

MEDIUM

Indico < 3.3.8 - Cross-Site Scripting in LaTeX Math Renderer

Title source: llm
STIX 2.1

Description

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, there is a Cross-Site-Scripting vulnerability when rendering LaTeX math code in contribution or abstract descriptions. Users should to update to Indico 3.3.8 as soon as possible. As a workaround, only let trustworthy users create content on Indico. Note that a conference doing a Call for Abstracts actively invites external speakers (who the organizers may not know and thus cannot fully trust) to submit content, hence the need to update to a a fixed version ASAP in particular when using such workflows.

References (2)

Core 2
Core References

Scores

CVSS v3 4.6
EPSS 0.0003
EPSS Percentile 10.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
cern/indico < 3.3.8
pypi/indico 0 - 3.3.8PyPI
Published Sep 10, 2025
Tracked Since Feb 18, 2026