CVE Explorer
CVE-2025-64187
OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vulnerability that allows injection of arbitrary HTML and JavaScript into Action Command notifications and prompts popups generated by the printer. An attacker who successfully convinces a victim to print a specially crafted file could exploit this issue to disrupt ongoing prints, extract information (including sensitive configuration settings, if the targeted user has the necessa
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"OctoPrint","vendor":"OctoPrint","versions":[{"status":"affected","version":"< 1.11.4"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f0bab81bd54065c89f614494c5bee5eadb50abd05f8bc7f77abe62f4d001c01c · sha256:61ef771bd8def605… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":4.6,"baseSeverity":"MEDIUM","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"LOW","subIntegrityImpact":"LOW","userInteraction":"ACTIVE","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:L/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"LOW","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f0bab81bd54065c89f614494c5bee5eadb50abd05f8bc7f77abe62f4d001c01c · sha256:61ef771bd8def605… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-80","description":"CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f0bab81bd54065c89f614494c5bee5eadb50abd05f8bc7f77abe62f4d001c01c · sha256:61ef771bd8def605… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"https://github.com/OctoPrint/OctoPrint/commit/9112e07b1085f4c1ee9eefc67985809251057a44","tags":["x_refsource_MISC"],"url":"https://github.com/OctoPrint/OctoPrint/commit/9112e07b1085f4c1ee9eefc67985809251057a44"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f0bab81bd54065c89f614494c5bee5eadb50abd05f8bc7f77abe62f4d001c01c · sha256:61ef771bd8def605… · /containers/cna/references/1
{"name":"https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-crvm-xjhm-9h29","tags":["x_refsource_CONFIRM"],"url":"https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-crvm-xjhm-9h29"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f0bab81bd54065c89f614494c5bee5eadb50abd05f8bc7f77abe62f4d001c01c · sha256:61ef771bd8def605… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.