VulnSea

octoprint vulnerabilities

CVEs whose affected-version data names the octoprint package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

11 CVEsRSS

CVE-2026-94490Medium· 4.7
today

A security flaw has been discovered in OctoPrint 1.0.0

A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of the file src/octoprint/server/api/system.py of the component Command API. Performing a manipulation of the argument co…

Sunlitvia NVD
CVE-2026-94489Medium· 4.3
today

A vulnerability was identified in OctoPrint 1.0.0

A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file src/octoprint/server/api/files.py of the component File Download API. Such manipulation of the argument filename lead…

Sunlitvia NVD
CVE-2026-35163Medium
1mo ago

OctoPrint provides a web interface for controlling consumer 3D printers

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/…

SunlitOctoPrint · OctoPrintEPSS 0.14%via NVD
CVE-2026-54134High
3mo ago

OctoPrint has possible file exfiltration via query parameters on upload endpoints

OctoPrint has possible file exfiltration via query parameters on upload endpoints

TwilightOctoPrint · OctoPrintEPSS 0.21%via GHSA
CVE-2026-23892Medium· 5.9
7mo ago

OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication

OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication

Sunlitoctoprint · octoprintEPSS 0.47%via OSV
CVE-2025-64187Medium
10mo ago

OctoPrint vulnerable to XSS in Action Commands Notification and Prompt

OctoPrint vulnerable to XSS in Action Commands Notification and Prompt

Sunlitoctoprint · octoprintEPSS 0.16%via OSV
CVE-2025-58180High· 8.8PoC
1y ago

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload

Midnightoctoprint · octoprintEPSS 21%via OSV
CVE-2025-48067Medium· 5.4
1y ago

OctoPrint vulnerable to possible file extraction via upload endpoints

OctoPrint vulnerable to possible file extraction via upload endpoints

Sunlitoctoprint · octoprintEPSS 0.29%via OSV
CVE-2025-48879Medium· 6.5
1y ago

OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint

OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint

Sunlitoctoprint · octoprintEPSS 0.26%via OSV
CVE-2024-23637Medium· 4.2
2y ago

OctoPrint Unverified Password Change via Access Control Settings

OctoPrint Unverified Password Change via Access Control Settings

Sunlitoctoprint · octoprintEPSS 0.52%via OSV
CVE-2022-2822Low· 3.7
4y ago

OctoPrint does not have rate limiting on the login page

OctoPrint does not have rate limiting on the login page

Sunlitoctoprint · octoprintEPSS 0.85%via OSV
octoprint vulnerabilities (CVEs) · VulnSea