CVE & Vulnerabilities · September 24, 2026
CVE-2026-94490 is an OS command injection bug in OctoPrint 1.0.0's Command API, specifically in the executeSystemCommand function handling the 'command' argument. A remote attacker can exploit it to run arbitrary system commands, and public proof-of-concept code is already circulating. The OctoPrint maintainers reportedly did not respond when notified ahead of disclosure, so no official patch is confirmed yet.
// source: nvd.nist.gov ↗