Path Traversal Vulnerability in OctoPrint 1.0.0 by OctoPrint Foundation
CVE-2026-94489
5.3MEDIUM
What is CVE-2026-94489?
A path traversal vulnerability has been discovered in OctoPrint 1.0.0 within the _validate function of the File Download API. This weakness allows attackers to manipulate the filename argument, potentially leading to unauthorized access to the file system. The exploit is publicly available, and the vulnerability can be exploited remotely, raising concerns over the security of users' systems. Efforts to communicate this issue to the vendor were unsuccessful, leaving systems vulnerable to potential misuse.
Affected Version(s)
OctoPrint 1.0.0
