PT-2026-51613 · Octoprint · Octoprint

CVE-2026-35163

·

Published

2026-06-23

·

Updated

2026-08-21

CVSS v4.0

4.6

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions OctoPrint versions prior to 1.11.8 OctoPrint versions 2.0.0rc1 through 2.0.0rc2
Description An issue allows the injection of arbitrary HTML and JavaScript into Suppressed Command notification popups generated by the printer. An attacker could exploit this by convincing a victim to print a specially crafted file, potentially disrupting ongoing prints, extracting sensitive configuration settings, or performing actions on behalf of the user within the instance.
Recommendations Update to version 1.11.8 or later. Update to version 2.0.0rc3 or later. Disable popups by setting OctoPrint Settings -> Serial Connection -> Behaviour -> Sanity Checking -> Display notifications for suppressed commands to Never show notifications. Ensure that files being printed originate from trusted sources and are sliced with the application's own slicer.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35163
GHSA-P6QX-GHXM-389H
PYSEC-2026-2688

Affected Products

Octoprint