Octoprint

Octoprint

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 2.1%
  • Veröffentlicht 22.09.2026 00:00:15
  • Zuletzt bearbeitet 22.09.2026 19:04:55

A security flaw has been discovered in OctoPrint 1.0.0. Affected by this issue is the function executeSystemCommand of the file src/octoprint/server/api/system.py of the component Command API. Performing a manipulation of the argument command results...

  • EPSS 0.37%
  • Veröffentlicht 21.09.2026 23:30:13
  • Zuletzt bearbeitet 22.09.2026 19:04:55

A vulnerability was identified in OctoPrint 1.0.0. Affected by this vulnerability is the function _validate of the file src/octoprint/server/api/files.py of the component File Download API. Such manipulation of the argument filename leads to path tra...

  • EPSS 0.21%
  • Veröffentlicht 21.08.2026 19:17:03
  • Zuletzt bearbeitet 30.09.2026 19:38:27

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and Flask with Werkzeug parse request parameters differently, allowing an attacker with FILE_UPLOAD permi...

  • EPSS 0.14%
  • Veröffentlicht 21.08.2026 19:17:01
  • Zuletzt bearbeitet 18.09.2026 20:09:01

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/octoprint/sta...

  • EPSS 0.48%
  • Veröffentlicht 27.01.2026 18:35:31
  • Zuletzt bearbeitet 02.02.2026 14:39:36

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up to and including 1.11.5 are affected by a (theoretical) timing attack vulnerability that allows API key extraction over the network. Due to using character...

  • EPSS 0.15%
  • Veröffentlicht 07.11.2025 03:11:34
  • Zuletzt bearbeitet 04.12.2025 21:37:04

OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vulnerability that allows injection of arbitrary HTML and JavaScript into Action Command notifications and prompts popups generated b...

  • EPSS 20.6%
  • Veröffentlicht 09.09.2025 19:34:14
  • Zuletzt bearbeitet 18.09.2025 17:37:54

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker to upload a file under a specially crafted filename that will allo...

  • EPSS 0.22%
  • Veröffentlicht 10.06.2025 15:23:54
  • Zuletzt bearbeitet 12.08.2025 13:32:55

OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows any unauthenticated attacker to send a manipulated broken multipart/form-data request to OctoPrint and through that make the web server component become unresponsive...

  • EPSS 0.26%
  • Veröffentlicht 10.06.2025 15:19:44
  • Zuletzt bearbeitet 12.08.2025 13:44:39

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows an attacker with the FILE_UPLOAD permission to exfiltrate files from the host that OctoPrint...

  • EPSS 0.24%
  • Veröffentlicht 22.04.2025 17:14:39
  • Zuletzt bearbeitet 27.06.2025 15:40:23

OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPrint has a vulnerability that allows an attacker to bypass the login redirect and directly access the rendered HTML of certain front...