PatchSiren

OctoPrint CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OctoPrint CVE published 2026-08-21

CVE-2026-54134

CVE-2026-54134 is a vulnerability in OctoPrint versions prior to 1.11.8 and 2.0.0rc3. This vulnerability allows an attacker with FILE_UPLOAD permission to inject reserved internal upload fields, potentially leading to arbitrary file uploads and configuration disclosure. The affected product is OctoPrint, a web interface for controlling consumer 3D printers. The vulnerability class is related to the custom [truncated]

MEDIUM OctoPrint CVE published 2026-08-21

CVE-2026-35163

CVE-2026-35163 is a vulnerability in OctoPrint's web interface that allows an attacker to inject HTML and JavaScript into notification popups, potentially disrupting prints, reading sensitive settings, or performing actions in the victim's session. The issue is fixed in versions 1.11.8 and 2.0.0rc3. OctoPrint administrators and users who use the web interface to control 3D printers should assess their exp [truncated]