CVE-2025-62169: OctoPrint-SpoolManager Plugin APIs do not enforce authentication
OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions 1.7.7 and older of the stable branch, the APIs of the OctoPrint-SpoolManager plugin do not correctly enforce authentication or authorization checks. This issue has been patched in versions 1.8.0a3 of the testing branch and 1.7.8 of the stable branch. The impact of this vulnerability is greatly reduced when using OctoPrint version 1.11.2 and newer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62169?
CVE-2025-62169 is considered a high severity vulnerability due to improper authentication checks in the OctoPrint-SpoolManager plugin.
How do I fix CVE-2025-62169?
To remediate CVE-2025-62169, update the OctoPrint-SpoolManager plugin to version 1.7.8 or later for stable branches or 1.8.0a2 or later for testing branches.
What are the affected versions for CVE-2025-62169?
CVE-2025-62169 affects OctoPrint-SpoolManager versions 1.8.0a2 and older in the testing branch and 1.7.7 and older in the stable branch.
What is the impact of CVE-2025-62169?
The impact of CVE-2025-62169 could allow unauthorized users to access sensitive API endpoints without proper authentication.
Who is vulnerable to CVE-2025-62169?
Users of the OctoPrint-SpoolManager plugin who are running affected versions are vulnerable to CVE-2025-62169.