CVE-2026-35163
Description
OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/octoprint/static/js/app/viewmodels/terminal.js without HTML escaping. An attacker who convinces a victim to print a crafted file can inject HTML and JavaScript into the notification, disrupt prints, read information available to the victim including sensitive settings when permitted, or perform actions in the victim's OctoPrint session. This issue is fixed in versions 1.11.8 and 2.0.0rc3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
OctoPrintPyPI | < 1.11.8 | 1.11.8 |
OctoPrintPyPI | >= 2.0.0rc1, < 2.0.0rc3 | 2.0.0rc3 |
Affected products
1Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-p6qx-ghxm-389hghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-35163ghsaADVISORY
- github.com/OctoPrint/OctoPrint/security/advisories/GHSA-p6qx-ghxm-389hnvdWEB
- github.com/pypa/advisory-database/tree/main/vulns/octoprint/PYSEC-2026-2688.yamlghsaWEB
- github.com/OctoPrint/OctoPrint/commit/42e0f9863935e136f04ed3c560cb96483a580d1bnvd
- github.com/OctoPrint/OctoPrint/commit/6e3db9096f8a94f7c2249be24b6d03a7d9c12bc7nvd
- github.com/OctoPrint/OctoPrint/releases/tag/1.11.8nvd
- github.com/OctoPrint/OctoPrint/releases/tag/2.0.0rc3nvd
News mentions
0No linked articles in our index yet.