---
id: CVE-2024-51330
title: >-
  An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker
  to execute arbitrary code via Inter-process communication (IPC) mechanism
  between Cura application and CuraEngine processes, localhost network stack,
  printing…
summary: >-
  An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker
  to execute arbitrary code via Inter-process communication (IPC) mechanism
  between Cura application and CuraEngine processes, localhost network stack,
  printing…
severity: medium
cvss: 5.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N'
cwe:
  - CWE-94
vendor: ultimaker
product: ultimaker_cura
affected:
  - ultimaker_cura <= 5.8.1
published: '2024-11-15'
updated: '2026-06-29'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-51330'
references:
  - url: 'https://gist.github.com/HalaAli198/ff06d7a94c06cdfb821dec4d6303e01b'
    label: cve@mitre.org
tags:
  - nvd
epss: 0.00197
epssPercentile: 0.08339
ingestedAt: '2026-06-29T21:48:47.197Z'
---

## Overview

An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application and CuraEngine processes, localhost network stack, printing settings and G-code processing and transmission components, Ultimaker 3D Printers.

## Affected

- `ultimaker_cura <= 5.8.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
