{"id":"CVE-2026-54134","summary":"OctoPrint: File exfiltration possible via query parameters on upload endpoints","details":"OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and Flask with Werkzeug parse request parameters differently, allowing an attacker with FILE_UPLOAD permission to inject reserved internal upload fields through query parameters or parser differentials despite the earlier GHSA-m9jh-jf9h-x3h2 fix. The affected endpoints are /api/files/{local|sdcard}, /api/languages, /plugin/backup/restore, and /plugin/pluginmanager/upload_file. An attacker can make OctoPrint treat an arbitrary host file as a temporary upload, move it into a downloadable upload directory, disclose configuration secrets or other readable files, and remove runtime files in a way that can affect a later restart. This issue is fixed in versions 1.11.8 and 2.0.0rc3.","aliases":["GHSA-j4h9-pm27-4rfw","PYSEC-2026-2687"],"modified":"2026-08-23T03:53:38.802395947Z","published":"2026-08-21T18:28:15.925Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-73"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54134.json"},"references":[{"type":"WEB","url":"https://github.com/OctoPrint/OctoPrint/releases/tag/1.11.8"},{"type":"WEB","url":"https://github.com/OctoPrint/OctoPrint/releases/tag/2.0.0rc3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54134.json"},{"type":"ADVISORY","url":"https://github.com/OctoPrint/OctoPrint/security/advisories/GHSA-j4h9-pm27-4rfw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54134"},{"type":"FIX","url":"https://github.com/OctoPrint/OctoPrint/commit/579148beeb6d6e9b3d41b1cf32309b47218ed380"},{"type":"FIX","url":"https://github.com/OctoPrint/OctoPrint/commit/8e3348197db867c30a32d13984f0bd0d664be413"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/octoprint/octoprint","events":[{"introduced":"0"},{"introduced":"d0268b28427c6dc632bccdc75433ba67e53a5650"},{"fixed":"42be7409d4820431043da48ece30014e26b47073"},{"fixed":"3e1fa9c6679df57bd50d425b90bef89e880d1385"},{"fixed":"579148beeb6d6e9b3d41b1cf32309b47218ed380"},{"fixed":"8e3348197db867c30a32d13984f0bd0d664be413"}],"database_specific":{"source":["AFFECTED_FIELD","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"1.11.8"},{"introduced":"2.0.0rc1"},{"fixed":"2.0.0rc3"}]}}],"versions":["2.0.0rc2","2.0.0rc1","1.11.7","1.11.6","1.11.5","1.11.4","1.11.3","1.11.2","1.11.1","1.11.0","1.10.3","1.10.2","1.10.1","1.10.0","1.9.3","1.9.2","1.9.0","1.8.7","1.8.6","1.8.5","1.8.4","1.8.3","1.8.2","1.8.1","1.8.0","1.7.3","1.7.2","1.7.1","1.6.1","1.5.3","1.5.2","1.5.1","1.5.0","1.5.0rc3","1.5.0rc2","1.5.0rc1","1.4.0rc6","1.4.0rc5","1.4.0rc4","1.4.0rc3","1.4.0rc2","1.4.0rc1","1.2.18","1.2.18rc1","1.2.17rc3","1.2.17rc2","1.2.17rc1","1.2.16","1.2.16rc2","1.2.16rc1","1.2.15","1.2.14","1.2.13","1.2.12","1.2.11","1.2.10","1.2.9","1.2.8","1.2.7","1.2.6","1.2.5","1.2.4","1.2.3","1.2.2","1.2.1","1.2.0","1.2.0-rc3","1.2.0-rc2","1.2.0-rc1","1.2.0-dev","1.1.0-dev"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54134.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N"}]}