affected: - package: ecosystem: PyPI name: octoprint purl: pkg:pypi/octoprint ranges: - events: - introduced: '0' - fixed: 3cca3a43f3d085e9bbe5a5840c8255bb1b5d052e repo: https://github.com/octoprint/octoprint type: GIT - events: - introduced: '0' - fixed: 1.8.3 type: ECOSYSTEM versions: - 1.3.11 - 1.3.12 - 1.3.12rc1 - 1.3.12rc3 - 1.4.0 - 1.4.0rc1 - 1.4.0rc2 - 1.4.0rc3 - 1.4.0rc4 - 1.4.0rc5 - 1.4.0rc6 - 1.4.1 - 1.4.1rc1 - 1.4.1rc2 - 1.4.1rc3 - 1.4.1rc4 - 1.4.2 - 1.5.0 - 1.5.0rc1 - 1.5.0rc2 - 1.5.0rc3 - 1.5.1 - 1.5.2 - 1.5.3 - 1.6.0 - 1.6.0rc1 - 1.6.0rc2 - 1.6.0rc3 - 1.6.1 - 1.7.0 - 1.7.0rc1 - 1.7.0rc2 - 1.7.0rc3 - 1.7.1 - 1.7.2 - 1.7.3 - 1.8.0 - 1.8.0rc1 - 1.8.0rc2 - 1.8.0rc3 - 1.8.0rc4 - 1.8.0rc5 - 1.8.1 - 1.8.2 aliases: - CVE-2022-3607 - GHSA-rj5f-vm79-5j84 details: Failure to Sanitize Special Elements into a Different Plane (Special Element Injection) in GitHub repository octoprint/octoprint prior to 1.8.3. id: PYSEC-2022-42975 modified: '2026-06-10T16:51:42.507412Z' published: '2022-10-19T13:15:00Z' references: - type: EVIDENCE url: https://huntr.dev/bounties/2d1db3c9-93e8-4902-a55b-5ea53c22aa11 - type: WEB url: https://huntr.dev/bounties/2d1db3c9-93e8-4902-a55b-5ea53c22aa11 - type: FIX url: https://github.com/octoprint/octoprint/commit/3cca3a43f3d085e9bbe5a5840c8255bb1b5d052e - type: ADVISORY url: https://github.com/advisories/GHSA-rj5f-vm79-5j84