CVE-2023-47268: Command Injection
Published May 8, 2026
·Updated
In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the project is sliced and G-code exported.
Affected Software
2 affected components
Prusa Research PrusaSlicer<=2.6.1
Prusa3d Prusaslicer<=2.6.1
Event History
May 8, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-47268?
CVE-2023-47268 is considered a high severity vulnerability due to its potential to execute arbitrary code.
2
How do I fix CVE-2023-47268?
To fix CVE-2023-47268, upgrade PrusaSlicer to version 2.6.2 or later.
3
What versions of PrusaSlicer are affected by CVE-2023-47268?
PrusaSlicer versions up to and including 2.6.1 are affected by CVE-2023-47268.
4
What types of files can exploit the vulnerability CVE-2023-47268?
CVE-2023-47268 can be exploited through crafted 3mf project files.
5
Is CVE-2023-47268 a local or remote vulnerability?
CVE-2023-47268 is a local vulnerability that requires accessing the host system where slicing occurs.