CVE-2025-48067
OctoPrint vulnerable to possible file extraction via upload endpoints
描述
### Impact OctoPrint versions up until and including 1.11.1 contain a vulnerability that allows an attacker with the `FILE_UPLOAD` permission to exfiltrate files from the host that OctoPrint has read access to, by moving them into the upload folder where they then can be downloaded from. The primary risk lies in the potential exfiltration of secrets stored inside OctoPrint's config, or further system files. By removing important runtime files, this could also be used to impact the availability of the host. Given that the attacker requires a user account with file upload permissions, the actual impact of this should however hopefully be minimal in most cases. ### Patches The vulnerability has been patched in version 1.11.2. ### Details A specially crafted HTTP Request to an affected upload endpoint that contains some form inputs only supposed to be used internally can be used to make OctoPrint move a file that it thinks is a freshly uploaded temporary one into its upload folder. The following endpoints in OctoPrint are affected: - `/api/files/{local|sdcard}` - `/api/languages` - `/plugin/backup/restore` - `/plugin/pluginmanager/upload_file` Further upload endpoints in third party plugins might be affected too. The fix removes any internal-only form inputs from incoming requests in the central file upload processor component. ### Credits This vulnerability was discovered and responsibly disclosed to OctoPrint by Jacopo Tediosi
如何修補 CVE-2025-48067
要修補 CVE-2025-48067,請將受影響套件升級到下列已修補版本。
- —升級至 1.11.2 或更新版本
- —升級至 1.11.2 或更新版本
CVE-2025-48067 正在被利用嗎?
低 — EPSS 為 0.3%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 1.11.2