CVE-2025-58180Disclosure(octoprint / octoprint)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

OctoPrint provides a web interface for controlling consumer 3D printers. OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker to upload a file under a specially crafted filename that will allow arbitrary command execution if said filename becomes included in a command defined in a system event handler and said event gets triggered. If no event handlers executing system commands with uploaded filenames as parameters have been configured, this vulnerability does not have an impact. The vulnerability is patched in version 1.11.3. As a workaround, OctoPrint administrators who have event handlers configured that include any kind of filename based placeholders should disable those by setting their `enabled` property to `False` or unchecking the "Enabled" checkbox in the GUI based Event Manager. Alternatively, OctoPrint administrators should set `feature.enforceReallyUniversalFilenames` to `true` in `config.yaml` and restart OctoPrint, then vet the existing uploads and make sure to delete any suspicious looking files. As always, OctoPrint administrators are advised to not expose OctoPrint on hostile networks like the public internet, and to vet who has access to their instance.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • octoprint

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
octoprint

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-12: 1PoC Mentioned / Linked · 2026-02-12: 1Technical Details · 2026-02-12: 102-12
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • Red Secure Tech Ltd.@redsecuretech
    Disclosure

    CVE-2025-58180 allows authenticated users to achieve RCE in OctoPrint ≤1.11.2 by uploading maliciously named files that trigger unsanitized shell commands in event handlers. https://redsecuretech.co.uk/blog/post/octoprint-1-11-2-authenticated-rce-via-file-upload/917 #Cybersecurity #CVE #OctoPrint #RCE #CommandInjection #3DPrinting #IoTSecurity https://t.co/W6Vn3HEiNm

    Post summary

    The post discloses CVE-2025-58180 as an authenticated remote code execution in OctoPrint versions up to 1.11.2, where malicious file uploads trigger unsanitized shell commands. A linked blog likely contains further technical details or a PoC.

    0101046
    41 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appoctoprintoctoprint---

Explore more