CVE-2025-48067

MEDIUM

OctoPrint <1.11.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows an attacker with the FILE_UPLOAD permission to exfiltrate files from the host that OctoPrint has read access to, by moving them into the upload folder where they then can be downloaded from. This vulnerability is fixed in 1.11.2.

Scores

CVSS v3 5.4
EPSS 0.0010
EPSS Percentile 27.6%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-73
Status published
Products (2)
octoprint/octoprint < 1.11.2
pypi/OctoPrint 0 - 1.11.2PyPI
Published Jun 10, 2025
Tracked Since Feb 18, 2026