CVE-2026-25505

CRITICAL

Pypi Bambuddy < 0.1.7 - Missing Authentication

Title source: rule

Description

Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.

Scores

CVSS v3 9.8
EPSS 0.0025
EPSS Percentile 47.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-321 CWE-306
Status published

Affected Products (2)

pypi/bambuddy < 0.1.7PyPI
bambuddy/bambuddy < 0.1.7

Timeline

Published Feb 04, 2026
Tracked Since Feb 18, 2026