Cross-Site Scripting in OctoPrint Web Interface for 3D Printers
CVE-2026-35163
4.6MEDIUM
What is CVE-2026-35163?
The OctoPrint web interface, designed for managing consumer 3D printers, has a vulnerability where notification popups fail to properly escape HTML content. This weakness allows an attacker to inject malicious HTML and JavaScript code through specially crafted print files. When a victim interacts with these notifications, the attacker can disrupt printer operations and potentially access sensitive information within the victim's session. The issue has been addressed in the software versions 1.11.8 and 2.0.0rc3, which enforce proper HTML escaping for user-generated content.
Affected Version(s)
OctoPrint < 1.11.8 < 1.11.8
OctoPrint >= 2.0.0rc1, < 2.0.0rc3 < 2.0.0rc1, 2.0.0rc3
