PyPI: indico

CVE-2026-33046

Safety vulnerability ID: SFTY-20260323-63655

Safety legacy ID: pyup.io-90352

Affected versions of the indico package are vulnerable to Command Injection due to insufficient sanitization of specially crafted LaTeX input in server-side LaTeX rendering. When XELATEX_PATH is enabled in indico.conf, Indico’s LaTeX rendering pipeline can be bypassed using obscure LaTeX syntax and underlying TeXLive flaws, allowing attacker-controlled snippets to read local files or execute commands with the privileges of the user running Indico on the server.

Created at: Jul 5, 2026Updated at: Jul 5, 2026

Overview

Indico discloses local files resulting in Remote Code Execution through LaTeX injection

Advisory

Affected versions of the indico package are vulnerable to Command Injection due to insufficient sanitization of specially crafted LaTeX input in server-side LaTeX rendering. When XELATEX_PATH is enabled in indico.conf, Indico’s LaTeX rendering pipeline can be bypassed using obscure LaTeX syntax and underlying TeXLive flaws, allowing attacker-controlled snippets to read local files or execute commands with the privileges of the user running Indico on the server.

Affected Package

Affecting indico package, versions
<3.3.12

Also affects

---

How to Fix

Upgrade
indico
to
3.3.12
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more