Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

octoprint — Vulnerabilities & Security Advisories 22

Browse all 22 CVE security advisories affecting octoprint. AI-powered Chinese analysis, POCs, and references for each vulnerability.

OctoPrint is an open-source host application for 3D printers, enabling remote monitoring and control via web interfaces. Its architecture, which bridges local hardware with network-accessible software, has historically exposed it to significant security risks. Record analysis reveals twenty Common Vulnerabilities and Exposures (CVEs), predominantly involving remote code execution, cross-site scripting, and privilege escalation flaws. These issues often stem from inadequate input validation and improper authentication mechanisms within the web server components. While no single catastrophic incident has defined its history, the cumulative effect of these vulnerabilities highlights the dangers of exposing embedded systems directly to networks without robust security hardening. The project’s reliance on community contributions has occasionally led to delayed patches, emphasizing the need for rigorous code review and secure configuration practices to mitigate the inherent risks of managing critical manufacturing infrastructure through internet-connected interfaces.

Found 14 results / 22 Clear Filters
Top products by octoprint: OctoPrint octoprint/octoprint
CVE ID Title CVSS Severity Published
CVE-2026-54134 OctoPrint: File exfiltration possible via query parameters on upload endpoints — OctoPrint CWE-73 7.0 High 2026-08-21
CVE-2026-35163 OctoPrint: XSS in Suppressed Command Notifications — OctoPrint CWE-80 4.6 Medium 2026-08-21
CVE-2026-23892 OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication — OctoPrint CWE-208 5.9AI Medium AI 2026-01-27
CVE-2025-64187 OctoPrint is vulnerable to XSS through Action Command Notifications and Prompts — OctoPrint CWE-80 6.1 - 2025-11-07
CVE-2025-58180 OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload — OctoPrint CWE-78 8.8AI High AI 2025-09-09
CVE-2025-48879 OctoPrint Vulnerable to Denial of Service through malformed HTTP request — OctoPrint CWE-140 6.5 Medium 2025-06-10
CVE-2025-48067 OctoPrint vulnerable to possible file extraction via upload endpoints — OctoPrint CWE-73 5.4 Medium 2025-06-10
CVE-2025-32788 OctoPrint Authenticated Reverse Proxy Page Authentication Bypass — OctoPrint CWE-290 4.3 Medium 2025-04-22
CVE-2024-49377 Jinja2 Templates are vulnerable to XSS attacks due to their configuration in OctoPrint — OctoPrint CWE-79 5.5 Medium 2024-11-05
CVE-2024-51493 API key access in settings without reauthentication in OctoPrint — OctoPrint CWE-620 5.3 Medium 2024-11-05
CVE-2024-32977 OctoPrint Authentication Bypass via X-Forwarded-For Header when autologinLocal is enabled — OctoPrint CWE-290 7.1 High 2024-05-14
CVE-2024-28237 OctoPrint XSS via the "Snapshot Test" feature in Classic Webcam plugin settings — OctoPrint CWE-79 4.0 Medium 2024-03-18
CVE-2024-23637 OctoPrint Unverified Password Change via Access Control Settings — OctoPrint CWE-287 4.2 Medium 2024-01-31
CVE-2023-41047 Improper Neutralization of Special Elements Used in a Template Engine in OctoPrint — OctoPrint CWE-1336 6.2 Medium 2023-10-09

This page lists every published CVE security advisory associated with octoprint. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.