CVE-2026-35163

Source
https://cve.org/CVERecord?id=CVE-2026-35163
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35163.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-35163
Aliases
Published
2026-08-21T18:25:49.564Z
Modified
2026-08-23T03:53:38.802750790Z
Severity
  • 4.6 (Medium) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N CVSS Calculator
Summary
OctoPrint: XSS in Suppressed Command Notifications
Details

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/octoprint/static/js/app/viewmodels/terminal.js without HTML escaping. An attacker who convinces a victim to print a crafted file can inject HTML and JavaScript into the notification, disrupt prints, read information available to the victim including sensitive settings when permitted, or perform actions in the victim's OctoPrint session. This issue is fixed in versions 1.11.8 and 2.0.0rc3.

Database specific
{
    "cwe_ids": [
        "CWE-80"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/35xxx/CVE-2026-35163.json"
}
References

Affected packages

Git / github.com/octoprint/octoprint

Affected ranges

Type
GIT
Repo
https://github.com/octoprint/octoprint
Events
Database specific
Show details
{
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.11.8"
        },
        {
            "introduced": "2.0.0rc1"
        },
        {
            "fixed": "2.0.0rc3"
        }
    ]
}

Affected versions

1.*
1.1.0-dev
1.10.0
1.10.0rc1
1.10.1
1.10.2
1.10.3
1.11.0
1.11.0rc1
1.11.1
1.11.2
1.11.3
1.11.4
1.11.5
1.11.6
1.11.7
1.2.0
1.2.0-dev
1.2.0-rc1
1.2.0-rc2
1.2.0-rc3
1.2.1
1.2.10
1.2.11
1.2.12
1.2.13
1.2.14
1.2.15
1.2.16
1.2.16rc1
1.2.16rc2
1.2.17rc1
1.2.17rc2
1.2.17rc3
1.2.18
1.2.18rc1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.2.7
1.2.8
1.2.9
1.4.0rc1
1.4.0rc2
1.4.0rc3
1.4.0rc4
1.4.0rc5
1.4.0rc6
1.5.0
1.5.0rc1
1.5.0rc2
1.5.0rc3
1.5.1
1.5.2
1.5.3
1.6.0rc1
1.6.1
1.7.0rc1
1.7.1
1.7.2
1.7.3
1.8.0
1.8.0rc1
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
1.8.6
1.8.7
1.9.0
1.9.0rc1
1.9.2
1.9.3
2.*
2.0.0rc1
2.0.0rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-35163.json"