CVE-2025-64187: OctoPrint provides a web interface for controlling consumer 3D printers. Versions 1.11.3 and below are affected by a vul
mediumvulnerability
security
Summary
OctoPrint, a web interface for controlling 3D printers, has a vulnerability in versions 1.11.3 and below that allows attackers to inject malicious HTML and JavaScript (code that runs in web browsers) into printer notifications. An attacker could trick a user into printing a specially crafted file to disrupt prints, steal sensitive information, or perform unauthorized actions on the user's OctoPrint system.
Solution / Mitigation
This issue is fixed in version 1.11.4. Users should update OctoPrint to version 1.11.4 or later.
Vulnerability Details
CVSS Score
4.4(medium)
EPSS (30-day exploit probability)
EPSS: 0.0%
Classification
Attack SophisticationModerate
Taxonomy References
CWE (Weakness Type)
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-64187
First tracked: February 15, 2026 at 08:52 PM
Classified by LLM (prompt v3) · confidence: 95%