Skip to content

Exported GCode contains OctoPrint API Key #22

@akloster

Description

@akloster

I manually inspected some GCode file and by accident discovered the following line:

; printhost_apikey = XXXXXXXXXXXXX

I would not classify this as a severe vulnerability, but I don't think users are aware that their gcode files now contain the access credentials to control their OctoPrint Host. Sharing GCode is rare, but it happens.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions