CVE-2026-35163

MEDIUM CVSS 4.0: 4.6 EPSS 0.14%
Updated Aug 21, 2026
Payload
Parameter Value
CVSS 4.6 (MEDIUM)
Type CWE-80 (Improper Neutralization of Script-Related HTML Tags (XSS))
Vendor Payload
Public PoC No

OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, Suppressed Command notification popups use PNotify rendering for printer-controlled payload.command and payload.message values in src/octoprint/static/js/app/viewmodels/terminal.js without HTML escaping. An attacker who convinces a victim to print a crafted file can inject HTML and JavaScript into the notification, disrupt prints, read information available to the victim including sensitive settings when permitted, or perform actions in the victim's OctoPrint session.

This issue is fixed in versions 1.11.8 and 2.0.0rc3.

Attack Parameters

Attack Vector
Local
Requires local access
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
None
No privileges needed
User Interaction
Active
User action required

Impact Assessment

Confidentiality
Low
Partial data leak
Integrity
Low
Partial data modification
Availability
Low
Partial disruption

CVSS Vector v4.0