CVE-2025-62169 Details
Description
OctoPrint-SpoolManager is a plugin for managing spools and all their usage metadata. In versions 1.8.0a2 and older of the testing branch and versions 1.7.7 and older of the stable branch, the APIs of the OctoPrint-SpoolManager plugin do not correctly enforce authentication or authorization checks. This issue has been patched in versions 1.8.0a3 of the testing branch and 1.7.8 of the stable branch. The impact of this vulnerability is greatly reduced when using OctoPrint version 1.11.2 and newer.
A vulnerability exists in the OctoPrint-SpoolManager plugin for managing spools and their usage metadata. In the stable branch versions through 1.7.7 and the testing branch versions through 1.8.0a2, the plugin's APIs fail to properly enforce authentication and authorization. This oversight allows unauthenticated users to access and modify the SpoolManager database, including deleting all data through a reset. However, the impact is significantly mitigated for users running OctoPrint version 1.11.2 or newer, where the database can only be reset to empty without authentication.
Users are advised to update to OctoPrint-SpoolManager version 1.8.0a3 on the testing branch or 1.7.8 on the stable branch. For those on OctoPrint 1.11.2 or newer, the database can only be reset to empty without authentication, but it is still recommended to install the update.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 23, 2025CISA-ADP
Assessed Oct 23, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| WildRikku OctoPrint-SpoolManager | All versions |
CPE
Remediation
| |
| OctoPrint | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 23, 2025 | New CVE Received | [email protected] |
Volerion