Impact
The vulnerability allows a malicious actor to embed HTML and JavaScript into the PNotify pop‑ups that display printer commands and messages. Because these values are inserted into the page without escaping, an attacker who can coax a user to print a crafted file can execute arbitrary script in the victim’s browser session. This can lead to information disclosure of sensitive OctoPrint settings, disruption of ongoing prints, or execution of unintended actions under the victim’s account.
Affected Systems
OctoPrint’s web interface, versions older than 1.11.8 and 2.0.0rc3
Risk and Exploitability
The CVSS score is 4.6, indicating moderate severity. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the victim to load a malicious G‑code file into OctoPrint, after which the embedded script runs in the local browser context. While the attack vector is not directly remote, it poses a risk to users who accept unknown print files, and the potential impact spans confidentiality, integrity, and availability within the user session.
OpenCVE Enrichment
Github GHSA