PyPI: indico
CVE-2026-33046
Safety vulnerability ID: SFTY-20260323-63655
Safety legacy ID: pyup.io-90352
Affected versions of the indico package are vulnerable to Command Injection due to insufficient sanitization of specially crafted LaTeX input in server-side LaTeX rendering. When XELATEX_PATH is enabled in indico.conf, Indico’s LaTeX rendering pipeline can be bypassed using obscure LaTeX syntax and underlying TeXLive flaws, allowing attacker-controlled snippets to read local files or execute commands with the privileges of the user running Indico on the server.
Overview
Indico discloses local files resulting in Remote Code Execution through LaTeX injection
Advisory
Affected versions of the indico package are vulnerable to Command Injection due to insufficient sanitization of specially crafted LaTeX input in server-side LaTeX rendering. When XELATEX_PATH is enabled in indico.conf, Indico’s LaTeX rendering pipeline can be bypassed using obscure LaTeX syntax and underlying TeXLive flaws, allowing attacker-controlled snippets to read local files or execute commands with the privileges of the user running Indico on the server.
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
References
- https://getsafety.com/vulnerabilities/SFTY-20260323-63655/CVE-2026-33046
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-33046
- https://data.safetycli.com/changelogs/indico/
- https://github.com/advisories/GHSA-rm2q-f7jv-3cfp
- https://pypi.org/project/indico
- https://github.com/indico/indico/security/advisories/GHSA-rm2q-f7jv-3cfp
- https://github.com/indico/indico/commit/0adb70f0ed66e129361d447868f5f3eb90dc5e96
- https://github.com/indico/indico/commit/1dbb12525b3de14229bf4d1ae192988068f975f6
- https://github.com/indico/indico/commit/5f24d23ce9c4b0e4b68b3d0b58987a948fc57c8a
- https://github.com/indico/indico/commit/fb169ced710c30cf792ce4b9f48688db0633cfd8
- https://github.com/indico/indico/releases/tag/v3.3.12
- https://nvd.nist.gov/vuln/detail/CVE-2026-33046
- https://github.com/advisories/GHSA-rm2q-f7jv-3cfp
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more
