EIP-2026-103810

PRE-CVE

PrusaSlicer 2.6.1 - Arbitrary code execution

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-103810. PoCs published by Kamil Breński.

AI-analyzed exploit summary This exploit demonstrates arbitrary code execution in PrusaSlicer up to version 2.6.1 by embedding malicious post-processing scripts in the 'Metadata/Slic3r_PE.config' file of a 3mf project. The PoC shows command execution on both Linux and Windows via the post_process setting during g-code export.

Description

PrusaSlicer 2.6.1 - Arbitrary code execution

Exploits (1)

exploitdb WORKING POC
by Kamil Breński · textlocalmultiple
https://www.exploit-db.com/exploits/51983

This exploit demonstrates arbitrary code execution in PrusaSlicer up to version 2.6.1 by embedding malicious post-processing scripts in the 'Metadata/Slic3r_PE.config' file of a 3mf project. The PoC shows command execution on both Linux and Windows via the post_process setting during g-code export.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: PrusaSlicer up to and including 2.6.1
No auth needed
Prerequisites: Victim must open or import a malicious 3mf project file · Victim must export g-code from the project
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026