Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-35163— OctoPrint: XSS in Suppressed Command Notifications

Quick assessment

Affected
OctoPrint OctoPrint
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OctoPrint 提供了用于控制消费级 3D 打印机的 Web 界面。在 1.11.8 和 2.0.0rc3 版本之前,被抑制的命令(Suppressed Command)通知弹窗在 中使用 PNotify 进行渲染时,直接显示了打印机控制的 和 值,而未进行 HTML 转义。攻击者若能诱使受害者打印一个精心构造的文件,便可在通知中注入 HTML 和 JavaScript 代码,从而中断打印任务、读取受害者可访问的信息(包括在允许的情况下读取敏感设置),或以受害者的身份在 OctoPrint 会话中执行操作。该问

CVSS 4.6 · Medium EPSS 0.14% · P3

Affected Version Matrix 2

VendorProduct Version RangeStatus
OctoPrint OctoPrint < 1.11.8 affected
>= 2.0.0rc1, < 2.0.0rc3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-35163

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OctoPrint: XSS in Suppressed Command Notifications
Source: CVE Program / CVE List V5
Vulnerability Description
OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/octoprint/static/js/app/viewmodels/terminal.js without HTML escaping. An attacker who convinces a victim to print a crafted file can inject HTML and JavaScript into the notification, disrupt prints, read information available to the victim including sensitive settings when permitted, or perform actions in the victim's OctoPrint session. This issue is fixed in versions 1.11.8 and 2.0.0rc3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
Web页面中脚本相关HTML标签转义处理不恰当(基本跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OctoPrint OctoPrint < 1.11.8 -

II. Public POCs for CVE-2026-35163

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-35163

登录查看更多情报信息。

Patches & Fixes for CVE-2026-35163 (2)

Vendor Advisories for CVE-2026-35163 (1)

Vendor Pages for CVE-2026-35163 (1)

Other References for CVE-2026-35163 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-35163

No comments yet


Leave a comment