{"schema_version":1,"title":"OctoPrint (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 24 vulnerabilities in OctoPrint (PyPI): 0 in the last 7 days and 8 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-54134, was published on 21 August 2026.","url":"https://junglewise.ai/threats/technologies/octoprint","json_url":"https://junglewise.ai/threats/technologies/octoprint.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/octoprint","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":1,"all_time":24,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":8,"last_365_days":8},"latest":[{"cve":"CVE-2026-54134","cvss":4,"epss":0.0032,"slug":"cve-2026-54134-octoprint-file-exfiltration-via-query-parameters-in-upload","title":"OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload han","severity":"high","exploited":false,"published_at":"2026-08-21T19:17:03.197+00:00","url":"https://junglewise.ai/threats/cve-2026-54134-octoprint-file-exfiltration-via-query-parameters-in-upload"},{"cve":"CVE-2026-35163","cvss":4,"epss":0.002,"slug":"cve-2026-35163-octoprint-xss-in-suppressed-command-notifications","title":"OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popup","severity":"medium","exploited":false,"published_at":"2026-08-21T19:17:01.17+00:00","url":"https://junglewise.ai/threats/cve-2026-35163-octoprint-xss-in-suppressed-command-notifications"},{"cve":"CVE-2026-23892","cvss":3.1,"epss":0.0044,"slug":"cve-2026-23892-octoprint-has-timing-side-channel-vulnerability-in-api-key","title":"PYSEC-2026-1716 - OctoPrint has Timing Side-Channel Vulnerability in API Key Authentication","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:20.785868+00:00","url":"https://junglewise.ai/threats/cve-2026-23892-octoprint-has-timing-side-channel-vulnerability-in-api-key"},{"cve":"CVE-2025-64187","cvss":4,"epss":0.0016,"slug":"cve-2025-64187-octoprint-vulnerable-to-xss-in-action-commands-notification-and","title":"PYSEC-2026-1714 - OctoPrint vulnerable to XSS in Action Commands Notification and Prompt","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:09.577264+00:00","url":"https://junglewise.ai/threats/cve-2025-64187-octoprint-vulnerable-to-xss-in-action-commands-notification-and"},{"cve":"CVE-2025-58180","cvss":3.1,"epss":0.2062,"slug":"cve-2025-58180-octoprint-is-vulnerable-to-rce-attacks-via-unsanitized-filename","title":"PYSEC-2026-1712 - OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:04.277623+00:00","url":"https://junglewise.ai/threats/cve-2025-58180-octoprint-is-vulnerable-to-rce-attacks-via-unsanitized-filename"},{"cve":"CVE-2025-48879","cvss":3.1,"epss":0.0026,"slug":"cve-2025-48879-octoprint-vulnerable-to-denial-of-service-through-malformed-http","title":"PYSEC-2026-1713 - OctoPrint Vulnerable to Denial of Service through malformed HTTP request in OctoPrint","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:54.373804+00:00","url":"https://junglewise.ai/threats/cve-2025-48879-octoprint-vulnerable-to-denial-of-service-through-malformed-http"},{"cve":"CVE-2025-48067","cvss":3.1,"epss":0.0029,"slug":"cve-2025-48067-octoprint-vulnerable-to-possible-file-extraction-via-upload","title":"PYSEC-2026-1715 - OctoPrint vulnerable to possible file extraction via upload endpoints","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:54.280924+00:00","url":"https://junglewise.ai/threats/cve-2025-48067-octoprint-vulnerable-to-possible-file-extraction-via-upload"},{"cve":"CVE-2022-2822","cvss":3.1,"epss":0.0085,"slug":"cve-2022-2822-octoprint-does-not-have-rate-limiting-on-the-login-page","title":"PYSEC-2026-887 - OctoPrint does not have rate limiting on the login page","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:31.877524+00:00","url":"https://junglewise.ai/threats/cve-2022-2822-octoprint-does-not-have-rate-limiting-on-the-login-page"},{"cve":"CVE-2025-32788","cvss":3.1,"epss":0.0025,"slug":"cve-2025-32788-octoprint-authenticated-reverse-proxy-page-authentication-bypass","title":"PYSEC-2025-56 - OctoPrint provides a web interface for controlling consumer 3D printers. In versions up to and including 1.10.3, OctoPrint has a vulnerabili","severity":"low","exploited":false,"published_at":"2025-04-22T18:15:59+00:00","url":"https://junglewise.ai/threats/cve-2025-32788-octoprint-authenticated-reverse-proxy-page-authentication-bypass"},{"cve":"CVE-2024-51493","cvss":3.1,"epss":0.0028,"slug":"cve-2024-51493-octoprint-has-api-key-access-in-settings-without-reauthentication","title":"PYSEC-2024-202 - OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain a vulnerab","severity":"low","exploited":false,"published_at":"2024-11-05T19:15:07+00:00","url":"https://junglewise.ai/threats/cve-2024-51493-octoprint-has-api-key-access-in-settings-without-reauthentication"},{"cve":"CVE-2024-49377","cvss":3.1,"epss":0.0027,"slug":"cve-2024-49377-octoprint-vulnerable-to-reflected-xss-in-jinja2-templates","title":"PYSEC-2024-201 - OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.2 contain reflected","severity":"low","exploited":false,"published_at":"2024-11-05T19:15:05+00:00","url":"https://junglewise.ai/threats/cve-2024-49377-octoprint-vulnerable-to-reflected-xss-in-jinja2-templates"},{"cve":"CVE-2024-32977","cvss":3.1,"epss":0.009,"slug":"cve-2024-32977-octoprint-authentication-bypass-via-x-forwarded-for-header","title":"PYSEC-2024-237 - OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerab","severity":"low","exploited":false,"published_at":"2024-05-14T16:17:12+00:00","url":"https://junglewise.ai/threats/cve-2024-32977-octoprint-authentication-bypass-via-x-forwarded-for-header"},{"cve":"CVE-2024-28237","cvss":3.1,"epss":0.0044,"slug":"cve-2024-28237-xss-via-the-snapshot-test-feature-in-classic-webcam-plugin","title":"PYSEC-2024-179 - OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.9.3 contain a vulnerabi","severity":"low","exploited":false,"published_at":"2024-03-18T22:15:07+00:00","url":"https://junglewise.ai/threats/cve-2024-28237-xss-via-the-snapshot-test-feature-in-classic-webcam-plugin"},{"cve":"CVE-2024-23637","cvss":3.1,"epss":0.0052,"slug":"cve-2024-23637-octoprint-unverified-password-change-via-access-control-settings","title":"PYSEC-2024-29 - OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious","severity":"low","exploited":false,"published_at":"2024-01-31T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-23637-octoprint-unverified-password-change-via-access-control-settings"},{"cve":"CVE-2023-41047","cvss":3.1,"epss":0.0057,"slug":"cve-2023-41047-octoprint-vulnerable-to-improper-neutralization-of-special","title":"PYSEC-2023-195 - OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a vulnerability that allows malicious","severity":"low","exploited":false,"published_at":"2023-10-09T16:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-41047-octoprint-vulnerable-to-improper-neutralization-of-special"},{"cve":"CVE-2022-3607","cvss":3,"epss":0.0042,"slug":"cve-2022-3607-octoprint-vulnerable-to-special-element-injection","title":"PYSEC-2022-42975 - Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.","severity":"low","exploited":false,"published_at":"2022-10-19T13:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3607-octoprint-vulnerable-to-special-element-injection"},{"cve":"CVE-2022-2888","cvss":3.1,"epss":0.003,"slug":"cve-2022-2888-octoprint-vulnerable-to-insufficient-session-expiration","title":"PYSEC-2022-282 - If an attacker comes into the possession of a victim's OctoPrint session cookie through whatever means, the attacker can use this cookie to","severity":"low","exploited":false,"published_at":"2022-09-21T12:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-2888-octoprint-vulnerable-to-insufficient-session-expiration"},{"cve":"CVE-2022-3068","cvss":3.1,"epss":0.0051,"slug":"cve-2022-3068-octoprint-privilege-escalation-in-plugin-manager","title":"PYSEC-2022-283 - Improper Privilege Management in GitHub repository octoprint/octoprint prior to 1.8.3.","severity":"low","exploited":false,"published_at":"2022-09-21T12:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-3068-octoprint-privilege-escalation-in-plugin-manager"},{"cve":"CVE-2022-2872","cvss":3,"epss":0.0068,"slug":"cve-2022-2872-octoprint-vulnerable-to-unrestricted-upload-of-file-with-dangerous","title":"PYSEC-2022-286 - Unrestricted Upload of File with Dangerous Type in GitHub repository octoprint/octoprint prior to 1.8.3.","severity":"low","exploited":false,"published_at":"2022-09-21T10:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-2872-octoprint-vulnerable-to-unrestricted-upload-of-file-with-dangerous"},{"cve":"CVE-2022-2930","cvss":3.1,"epss":0.0035,"slug":"cve-2022-2930-octoprint-unverified-password-change","title":"PYSEC-2022-43142 - Unverified Password Change in GitHub repository octoprint/octoprint prior to 1.8.3.","severity":"low","exploited":false,"published_at":"2022-08-22T12:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-2930-octoprint-unverified-password-change"},{"cve":"CVE-2022-1432","cvss":3,"epss":0.0121,"slug":"cve-2022-1432-cross-site-scripting-in-octoprint","title":"PYSEC-2022-201 - Cross-site Scripting (XSS) - Generic in GitHub repository octoprint/octoprint prior to 1.8.0.","severity":"low","exploited":false,"published_at":"2022-05-18T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-1432-cross-site-scripting-in-octoprint"},{"cve":"CVE-2022-1430","cvss":3,"epss":0.0134,"slug":"cve-2022-1430-cross-site-scripting-in-octoprint","title":"PYSEC-2022-200 - Cross-site Scripting (XSS) - DOM in GitHub repository octoprint/octoprint prior to 1.8.0.","severity":"low","exploited":false,"published_at":"2022-05-18T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2022-1430-cross-site-scripting-in-octoprint"},{"cve":"CVE-2021-32560","cvss":3.1,"epss":0.015,"slug":"cve-2021-32560-octoprint-incorrect-access-control","title":"PYSEC-2021-29 - The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files.","severity":"low","exploited":false,"published_at":"2021-05-11T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32560-octoprint-incorrect-access-control"},{"cve":"CVE-2021-32561","cvss":3.1,"epss":0.0115,"slug":"cve-2021-32561-octoprint-api-error-messages-vulnerable-to-xss","title":"PYSEC-2021-30 - OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.","severity":"low","exploited":false,"published_at":"2021-05-11T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32561-octoprint-api-error-messages-vulnerable-to-xss"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":6},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"OctoPrint (PyPI)","slug":"octoprint","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://octoprint.org/","repo_url":"https://github.com/OctoPrint/OctoPrint","description":"An open-source web interface for 3D printers that allows for remote monitoring and control.","url":"https://junglewise.ai/threats/technologies/octoprint"},"most_severe":[{"cve":"CVE-2026-54134","cvss":4,"epss":0.0032,"slug":"cve-2026-54134-octoprint-file-exfiltration-via-query-parameters-in-upload","title":"OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload han","severity":"high","exploited":false,"published_at":"2026-08-21T19:17:03.197+00:00","url":"https://junglewise.ai/threats/cve-2026-54134-octoprint-file-exfiltration-via-query-parameters-in-upload"},{"cve":"CVE-2026-35163","cvss":4,"epss":0.002,"slug":"cve-2026-35163-octoprint-xss-in-suppressed-command-notifications","title":"OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popup","severity":"medium","exploited":false,"published_at":"2026-08-21T19:17:01.17+00:00","url":"https://junglewise.ai/threats/cve-2026-35163-octoprint-xss-in-suppressed-command-notifications"},{"cve":"CVE-2025-64187","cvss":4,"epss":0.0016,"slug":"cve-2025-64187-octoprint-vulnerable-to-xss-in-action-commands-notification-and","title":"PYSEC-2026-1714 - OctoPrint vulnerable to XSS in Action Commands Notification and Prompt","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:09.577264+00:00","url":"https://junglewise.ai/threats/cve-2025-64187-octoprint-vulnerable-to-xss-in-action-commands-notification-and"},{"cve":"CVE-2025-58180","cvss":3.1,"epss":0.2062,"slug":"cve-2025-58180-octoprint-is-vulnerable-to-rce-attacks-via-unsanitized-filename","title":"PYSEC-2026-1712 - OctoPrint is Vulnerable to RCE Attacks via Unsanitized Filename in File Upload","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:04.277623+00:00","url":"https://junglewise.ai/threats/cve-2025-58180-octoprint-is-vulnerable-to-rce-attacks-via-unsanitized-filename"},{"cve":"CVE-2021-32560","cvss":3.1,"epss":0.015,"slug":"cve-2021-32560-octoprint-incorrect-access-control","title":"PYSEC-2021-29 - The Logging subsystem in OctoPrint before 1.6.0 has incorrect access control because it attempts to manage files that are not *.log files.","severity":"low","exploited":false,"published_at":"2021-05-11T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32560-octoprint-incorrect-access-control"},{"cve":"CVE-2021-32561","cvss":3.1,"epss":0.0115,"slug":"cve-2021-32561-octoprint-api-error-messages-vulnerable-to-xss","title":"PYSEC-2021-30 - OctoPrint before 1.6.0 allows XSS because API error messages include the values of input parameters.","severity":"low","exploited":false,"published_at":"2021-05-11T14:15:00+00:00","url":"https://junglewise.ai/threats/cve-2021-32561-octoprint-api-error-messages-vulnerable-to-xss"},{"cve":"CVE-2024-32977","cvss":3.1,"epss":0.009,"slug":"cve-2024-32977-octoprint-authentication-bypass-via-x-forwarded-for-header","title":"PYSEC-2024-237 - OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.10.0 contain a vulnerab","severity":"low","exploited":false,"published_at":"2024-05-14T16:17:12+00:00","url":"https://junglewise.ai/threats/cve-2024-32977-octoprint-authentication-bypass-via-x-forwarded-for-header"},{"cve":"CVE-2022-2822","cvss":3.1,"epss":0.0085,"slug":"cve-2022-2822-octoprint-does-not-have-rate-limiting-on-the-login-page","title":"PYSEC-2026-887 - OctoPrint does not have rate limiting on the login page","severity":"low","exploited":false,"published_at":"2026-07-06T08:03:31.877524+00:00","url":"https://junglewise.ai/threats/cve-2022-2822-octoprint-does-not-have-rate-limiting-on-the-login-page"},{"cve":"CVE-2023-41047","cvss":3.1,"epss":0.0057,"slug":"cve-2023-41047-octoprint-vulnerable-to-improper-neutralization-of-special","title":"PYSEC-2023-195 - OctoPrint is a web interface for 3D printers. OctoPrint versions up until and including 1.9.2 contain a vulnerability that allows malicious","severity":"low","exploited":false,"published_at":"2023-10-09T16:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-41047-octoprint-vulnerable-to-improper-neutralization-of-special"},{"cve":"CVE-2024-23637","cvss":3.1,"epss":0.0052,"slug":"cve-2024-23637-octoprint-unverified-password-change-via-access-control-settings","title":"PYSEC-2024-29 - OctoPrint is a web interface for 3D printer.s OctoPrint versions up until and including 1.9.3 contain a vulnerability that allows malicious","severity":"low","exploited":false,"published_at":"2024-01-31T18:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-23637-octoprint-unverified-password-change-via-access-control-settings"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}