---
id: CVE-2026-94489
title: A vulnerability was identified in OctoPrint 1.0.0
summary: >-
  A vulnerability was identified in OctoPrint 1.0.0. Affected by this
  vulnerability is the function _validate of the file
  src/octoprint/server/api/files.py of the component File Download API. Such
  manipulation of the argument filename lead…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-22
product: OctoPrint
affected:
  - OctoPrint 1.0.0
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:04:55.677'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94489'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-94489'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/895338'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408189'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/408189/cti'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/895338'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-22T13:23:59.303161Z'
ingestedAt: '2026-09-21T23:55:16.587Z'
epss: 0.00365
epssPercentile: 0.3035
---

## Overview

A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file src/octoprint/server/api/files.py of the component File Download API. Such manipulation of the argument filename leads to path traversal. The attack may be performed from remote. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
