PT-2025-24682 · Octoprint · Octoprint

Jacopotediosi

·

Published

2025-06-10

·

Updated

2025-08-12

·

CVE-2025-48067

CVSS v3.1

5.4

Medium

VectorAV:A/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions OctoPrint versions up to and including 1.11.1
Description The issue affects a web interface for controlling consumer 3D printers, allowing an attacker with the FILE UPLOAD permission to exfiltrate files from the host by moving them into the upload folder, from where they can be downloaded.
Recommendations For versions up to and including 1.11.1, update to version 1.11.2 to resolve the issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-48067
GHSA-M9JH-JF9H-X3H2

Affected Products

Octoprint