Path Traversal Vulnerability in OctoPrint 1.0.0 by OctoPrint Foundation
CVE-2026-94489

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-94489?

A path traversal vulnerability has been discovered in OctoPrint 1.0.0 within the _validate function of the File Download API. This weakness allows attackers to manipulate the filename argument, potentially leading to unauthorized access to the file system. The exploit is publicly available, and the vulnerability can be exploited remotely, raising concerns over the security of users' systems. Efforts to communicate this issue to the vendor were unsuccessful, leaving systems vulnerable to potential misuse.

Affected Version(s)

OctoPrint 1.0.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

EagleShadow (VulDB User)
VulDB CNA Team
.