OctoPrint's security policy can be found here.
Security: OctoPrint/OctoPrint
Security
SECURITY.md
-
XSS in Action Commands Notification and PromptGHSA-crvm-xjhm-9h29 published
Nov 4, 2025 by fooselModerate -
RCE in OctoPrint via Unsanitized Filename in File UploadGHSA-49mj-x8jp-qvfc published
Sep 9, 2025 by fooselHigh -
Denial of Service through malformed HTTP request in OctoPrintGHSA-9wj4-8h85-pgrw published
Jun 10, 2025 by fooselModerate -
File exfiltration possible via upload endpointsGHSA-m9jh-jf9h-x3h2 published
Jun 10, 2025 by fooselModerate -
Authenticated Reverse Proxy Page Authentication BypassGHSA-qw93-h6pf-226x published
Apr 22, 2025 by fooselModerate -
API key access in settings without reauthenticationGHSA-cc6x-8cc7-9953 published
Nov 5, 2024 by fooselModerate -
Jinja2 Templates are vulnerable to XSS attacks due to their configuration in OctoPrintGHSA-xvxq-g8hw-fx4g published
Nov 5, 2024 by fooselModerate -
Authentication Bypass via X-Forwarded-For Header when autologinLocal is enabledGHSA-2vjq-hg5w-5gm7 published
May 14, 2024 by fooselHigh -
XSS via the "Snapshot Test" feature in Classic Webcam plugin settingsGHSA-x7mf-wrh9-r76c published
Mar 18, 2024 by fooselModerate -
Unverified Password Change via Access Control SettingsGHSA-5626-pw9c-hmjr published
Jan 31, 2024 by fooselModerate
Learn more about advisories related to OctoPrint/OctoPrint in the GitHub Advisory Database