CVE-2026-35163 MEDIUM

CVE-2026-35163: OctoPrint: XSS in Suppressed Command Notifications

Vendor Octoprint
Product OctoPrint
Weakness CWE-80 · XSS · basic
Published August 21, 2026
Last update August 21, 2026

CVSS base score

4.6/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N

What the vulnerability does

01Description

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/octoprint/static/js/app/viewmodels/terminal.js without HTML escaping. An attacker who convinces a victim to print a crafted file can inject HTML and JavaScript into the notification, disrupt prints, read information available to the victim including sensitive settings when permitted, or perform actions in the victim's OctoPrint session. This issue is fixed in versions 1.11.8 and 2.0.0rc3.

Key dates

02Disclosure timeline

August 21, 2026 CVE published
August 21, 2026 Record updated

Related vulnerabilities

04Related CVE