CVE-2026-54134 is a vulnerability in OctoPrint versions prior to 1.11.8 and 2.0.0rc3. This vulnerability allows an attacker with FILE_UPLOAD permission to inject reserved internal upload fields, potentially leading to arbitrary file uploads and configuration disclosure. The affected product is OctoPrint, a web interface for controlling consumer 3D printers. The vulnerability class is related to the custom [truncated]
OctoPrint provides a web interface for controlling consumer 3D printers. The vulnerability, CVE-2026-35163, is related to Suppressed Command notification popups using PNotify rendering for printer-controlled payload.command and payload.message values without HTML escaping. This allows an attacker to inject HTML and JavaScript into the notification, disrupting prints, reading information available to the v [truncated]