Executive brief
OctoPrint is a popular open-source web interface for 3D printer control and monitoring. When the autologinLocal feature is enabled, attackers can bypass authentication entirely by spoofing their IP address through the X-Forwarded-For header, gaining unauthorized access to printer management and control functions without requiring valid credentials.
Technical details
This is an authentication bypass vulnerability (CWE-290: Authentication Bypass by Spoofing) in OctoPrint's IP-based local network detection logic. When autologinLocal is enabled in config.yaml, the application trusts the X-Forwarded-For HTTP header to determine if a request originates from a local network, allowing automatic login without credentials. An unauthenticated attacker can spoof this header (e.g., set X-Forwarded-For: 127.0.0.1) to trick the application into auto-logging them in as a configured user. The attack requires network access to the OctoPrint instance and the autologinLocal feature to be explicitly enabled; the vulnerability is network-adjacent in attack vector and does not require user interaction. The fix has been released in version 1.10.1.
Affected products
- OctoPrint OctoPrint up to and including 1.10.0
Timeline
- 2024-05-14: disclosed
- 2024-05-14: patched: Fixed in version 1.10.1