PT-2025-24682 · Octoprint · Octoprint

·

CVE-2025-48067

·

Published

2025-06-10

·

Updated

2026-07-07

CVSS v3.1

5.4

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions OctoPrint versions up to and including 1.11.1
Description The issue affects a web interface for controlling consumer 3D printers, allowing an attacker with the FILE UPLOAD permission to exfiltrate files from the host by moving them into the upload folder, from where they can be downloaded.
Recommendations For versions up to and including 1.11.1, update to version 1.11.2 to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-48067
GHSA-M9JH-JF9H-X3H2
PYSEC-2026-1715

Affected Products

Octoprint