Cross-Site Scripting in OctoPrint Web Interface for 3D Printers
CVE-2026-35163

4.6MEDIUM

Key Information:

Vendor

Octoprint

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-35163?

The OctoPrint web interface, designed for managing consumer 3D printers, has a vulnerability where notification popups fail to properly escape HTML content. This weakness allows an attacker to inject malicious HTML and JavaScript code through specially crafted print files. When a victim interacts with these notifications, the attacker can disrupt printer operations and potentially access sensitive information within the victim's session. The issue has been addressed in the software versions 1.11.8 and 2.0.0rc3, which enforce proper HTML escaping for user-generated content.

Affected Version(s)

OctoPrint < 1.11.8 < 1.11.8

OctoPrint >= 2.0.0rc1, < 2.0.0rc3 < 2.0.0rc1, 2.0.0rc3

References

CVSS V4

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.