CVE-2025-64187
MEDIUMOctoPrint < 1.11.4 - Stored Cross-Site Scripting via Action Command Notifications
Title source: llmDescription
OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vulnerability that allows injection of arbitrary HTML and JavaScript into Action Command notifications and prompts popups generated by the printer. An attacker who successfully convinces a victim to print a specially crafted file could exploit this issue to disrupt ongoing prints, extract information (including sensitive configuration settings, if the targeted user has the necessary permissions for that), or perform other actions on behalf of the targeted user within the OctoPrint instance. This issue is fixed in version 1.11.4.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-crvm-xjhm-9h29
Scores
CVSS v3
4.4
EPSS
0.0013
EPSS Percentile
2.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-80
Status
published
Products (2)
octoprint/octoprint
< 1.11.4
pypi/octoprint
0 - 1.11.4PyPI
Published
Nov 07, 2025
Tracked Since
Feb 18, 2026