CVE-2026-35163Medium▾ SunlitOctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 22.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/octoprint/static/js/app/viewmodels/terminal.js without HTML escaping. An attacker who convinces a victim to print a crafted file can inject HTML and JavaScript into the notification, disrupt prints, read information available to the victim including sensitive settings when permitted, or perform actions in the victim's OctoPrint session. This issue is fixed in versions 1.11.8 and 2.0.0rc3.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
OctoPrint <= 1.11.7OctoPrint >= 2.0.0rc1, <= 2.0.0rc2Patched in:
OctoPrint 1.11.8OctoPrint 2.0.0rc3Connected by shared product, vendor, weakness, or advisory.
CVE-2024-23637Medium· 4.2OctoPrint Unverified Password Change via Access Control Settings
CVE-2026-23892Medium· 5.9OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication
CVE-2025-48067Medium· 5.4OctoPrint vulnerable to possible file extraction via upload endpoints
CVE-2025-64187MediumOctoPrint vulnerable to XSS in Action Commands Notification and Prompt
CVE-2025-48879Medium· 6.5OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint
CVE-2022-2822Low· 3.7OctoPrint does not have rate limiting on the login page