CVE-2025-48067Medium· 5.4▾ SunlitOctoPrint vulnerable to possible file extraction via upload endpoints
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
0.3% → 0.3%
OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows an attacker with the FILE_UPLOAD permission to exfiltrate files from the host that OctoPrint has read access to, by moving them into the upload folder where they then can be downloaded from.
The primary risk lies in the potential exfiltration of secrets stored inside OctoPrint's config, or further system files. By removing important runtime files, this could also be used to impact the availability of the host. Given that the attacker requires a user account with file upload permissions, the actual impact of this should however hopefully be minimal in most cases.
The vulnerability has been patched in version 1.11.2.
A specially crafted HTTP Request to an affected upload endpoint that contains some form inputs only supposed to be used internally can be used to make OctoPrint move a file that it thinks is a freshly uploaded temporary one into its upload folder.
The following endpoints in OctoPrint are affected:
/api/files/{local|sdcard}/api/languages/plugin/backup/restore/plugin/pluginmanager/upload_fileFurther upload endpoints in third party plugins might be affected too.
The fix removes any internal-only form inputs from incoming requests in the central file upload processor component.
This vulnerability was discovered and responsibly disclosed to OctoPrint by Jacopo Tediosi
octoprint < 1.11.2Upgrade to a patched release:
octoprint 1.11.2Connected by shared product, vendor, weakness, or advisory.
CVE-2024-23637Medium· 4.2OctoPrint Unverified Password Change via Access Control Settings
CVE-2026-23892Medium· 5.9OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication
CVE-2025-64187MediumOctoPrint vulnerable to XSS in Action Commands Notification and Prompt
CVE-2025-48879Medium· 6.5OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint
CVE-2025-58180High· 8.8OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload
CVE-2022-2822Low· 3.7OctoPrint does not have rate limiting on the login page