Vulnerabilities & PatchesEmerging1 src
CVE-2026-54134 - OctoPrint: File exfiltration possible via query parameters on upload endpoints
CVE ID : CVE-2026-54134
Published : Aug. 21, 2026, 6:28 p. m.
• 42 minutes ago
Description : OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1. 11. 8 and 2. 0. 0rc3, OctoPrint's custom Tornado upload handler and Flask with Werkzeug parse request parameters differently, allowing an attacker with FILE_UPLOAD permission to inject reserved internal upload fields through query parameters or parser differentials despite the earlier GHSA-m9jh-jf9h-x3h2 fix.
The affected endpoints are /api/files/{local
• sdcard}, /api/languages, /plugin/backup/restore, and /plugin/pluginmanager/upload_file. An attacker can make OctoPrint treat an arbitrary host file as a temporary upload, move it into a downloadable upload directory, disclose configuration secrets or other readable files, and remove runtime files in a way that can affect a later restart.