CVE-2026-25505
CRITICALPypi Bambuddy < 0.1.7 - Missing Authentication
Title source: ruleDescription
Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.
Scores
CVSS v3
9.8
EPSS
0.0025
EPSS Percentile
47.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-321
CWE-306
Status
published
Affected Products (2)
pypi/bambuddy
< 0.1.7PyPI
bambuddy/bambuddy
< 0.1.7
Timeline
Published
Feb 04, 2026
Tracked Since
Feb 18, 2026