Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54134— OctoPrint: File exfiltration possible via query parameters on upload endpoints

Quick assessment

Affected
OctoPrint OctoPrint
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

OctoPrint 是一个用于控制消费级 3D 打印机的 Web 界面。在版本 1.11.8 及 2.0.0rc3 之前,OctoPrint 的自定义 Tornado 上传处理程序与使用 Werkzeug 的 Flask 框架在解析请求参数时存在差异。这种差异使得拥有 FILE_UPLOAD 权限的攻击者能够通过查询参数或解析器差异注入保留的内部上传字段,从而绕过了先前 GHSA-m9jh-jf9h-x3h2 修复措施的效果。受影响的端点包括 、 、 和 。 攻击者可以利用此漏洞使 OctoPrint 将任意主机上

CVSS 7.0 · High EPSS 0.21% · P12

Affected Version Matrix 2

VendorProduct Version RangeStatus
OctoPrint OctoPrint < 1.11.8 affected
>= 2.0.0rc1, < 2.0.0rc3 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54134

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
OctoPrint: File exfiltration possible via query parameters on upload endpoints
Source: CVE Program / CVE List V5
Vulnerability Description
OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and Flask with Werkzeug parse request parameters differently, allowing an attacker with FILE_UPLOAD permission to inject reserved internal upload fields through query parameters or parser differentials despite the earlier GHSA-m9jh-jf9h-x3h2 fix. The affected endpoints are /api/files/{local|sdcard}, /api/languages, /plugin/backup/restore, and /plugin/pluginmanager/upload_file. An attacker can make OctoPrint treat an arbitrary host file as a temporary upload, move it into a downloadable upload directory, disclose configuration secrets or other readable files, and remove runtime files in a way that can affect a later restart. This issue is fixed in versions 1.11.8 and 2.0.0rc3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
文件名或路径的外部可控制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
OctoPrint OctoPrint < 1.11.8 -

II. Public POCs for CVE-2026-54134

# POC Description Source Link Shenlong Link
AI-Generated POC Premium
Qwen3.6-35B-A3B · 6980 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-54134

登录查看更多情报信息。

Vendor Advisories for CVE-2026-54134 (1)

Vendor Pages for CVE-2026-54134 (1)

Other References for CVE-2026-54134 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54134

No comments yet


Leave a comment