OctoPrint

Design Tools

The snappy web interface for your 3D printer.

Latest 1.11.8 · by Gina HäußgeWebsiteOctoPrint/OctoPrint

Release activity

Release activity — 10 releases across 9 days since Sep 9, 2025. Each cell is one day; darker means more releases that day. Nothing is recorded before Sep 9, 2025. Older weeks are hidden at this screen width.
MayJunJulAug
SundayNo releases on Apr 26, 2026No releases on May 3, 2026No releases on May 10, 2026No releases on May 17, 2026No releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026
Monday1 release on Apr 27, 2026No releases on May 4, 2026No releases on May 11, 2026No releases on May 18, 2026No releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026
TuesdayNo releases on Apr 28, 2026No releases on May 5, 2026No releases on May 12, 20261 release on May 19, 2026No releases on May 26, 2026No releases on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 20262 releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 20261 release on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026No releases on Aug 11, 2026
WednesdayNo releases on Apr 29, 2026No releases on May 6, 2026No releases on May 13, 2026No releases on May 20, 2026No releases on May 27, 2026No releases on Jun 3, 2026No releases on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026
ThursdayNo releases on Apr 30, 2026No releases on May 7, 2026No releases on May 14, 2026No releases on May 21, 2026No releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026
FridayNo releases on May 1, 2026No releases on May 8, 2026No releases on May 15, 2026No releases on May 22, 2026No releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026
SaturdayNo releases on May 2, 2026No releases on May 9, 2026No releases on May 16, 2026No releases on May 23, 2026No releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026

10 releases since Sep 9, 2025, busiest day 2

Changelog

2.0.0rc4

Pre-release
Fixed 1
  • Limit settings paths available with SETTINGS_READ permission to frontend relevant settings
Security 1
  • Add reauth requirement for setting defaultReauthenticationTimeout via UI/settings API
⚠️ Important note on release candidates

This is a Release Candidate of OctoPrint. It is not a stable release: severe bugs can occur, and they can be bad enough that they make a manual downgrade to an earlier version necessary - maybe even from the command line.

You should be comfortable with and capable of possibly having to do this before installing an RC.

🔁 Feedback on this RC

Please provide general feedback on this RC in this ticket. An "All is working fine" is valuable feedback as well because it tells me people are actually testing this RC and just not finding problems with it.

If you run into any obvious bugs, please follow "How to file a bug report" - I need logs and reproduction steps to fix issues, not just the information that something doesn't work.

Thanks!

Things to take a closer look at

For this RC, these things should get a closer look while testing, if possible:

  1. proper behaviour when using the included web interface as well as any third party clients at your disposal
  2. printing via a serial connection
  3. managing files on your printer's storage via a serial connection
  4. blocklisted serial ports and/or baud rates are properly migrated to the serial connector (one per line, not comma-separated)
  5. if your printer's disconnected state happens to be "after error", please report back on which connector you used and what the reported error is
  6. if you have a Klipper/Moonraker based printer available: can you use it through OctoPrint when you install the Moonraker Connector?
  7. if you have a Bambu based printer available: can you use it through OctoPrint when you install the Bambu Connector?

[!NOTE] As I'm still seeing a lot of so far unexplained "error" states, please take special note of item 5!

✋ Heads-ups

The heads-ups from 2.0.0rc1 still apply!

🐛 Bug fixes
Core
  • #5425: Add reauth requirement for setting defaultReauthenticationTimeout via UI/settings API.
  • #5429: Limit settings paths available with SETTINGS_READ permission to frontend relevant settings.
🎉 Special thanks to all the contributors!

Special thanks to everyone who contributed to this RC and provided full, analyzable bug reports!

🔗 More information
View originalPermalink
How 2.0.0rc4 went

2.0.0rc3

Pre-release
Added 5
  • Add the used printer connector to various printer related events
  • Add support for hiding non-stock marks on the temperature graph
  • Add Printing chart marker showing start of actual job processing after initial preheating and leveling
  • Add more filter options to the plugin repository browser to filter out commercial or AI developed plugins
  • Add display of the ai-developed attribute in the plugin repository
Changed 1
  • Update gcode-thumbnail-tool to fix extraction of thumbnails generated by Creality Print 7.x
Fixed 6
  • Fix Hide successfully printed files option in the file list breaking its processing due to JS errors inside the filter
  • Fix /api/job throwing an error in case of a non-int progress
  • Fix crash in Printer.get_current_temperatures when printer connector doesn't support temperature offsets
  • Fix download filenames containing a comma
  • Fix stopping and starting of analysis queue
  • Fix versioning without available tags
Security 2
  • Fix XSS in Suppressed Command Notifications allowing injection of arbitrary HTML and JavaScript into notifications
  • Fix file exfiltration vulnerability via parameter injection on upload endpoints
⚠️ Important note on release candidates

This is a Release Candidate of OctoPrint. It is not a stable release: severe bugs can occur, and they can be bad enough that they make a manual downgrade to an earlier version necessary - maybe even from the command line.

You should be comfortable with and capable of possibly having to do this before installing an RC.

🔁 Feedback on this RC

Please provide general feedback on this RC in this ticket. An "All is working fine" is valuable feedback as well because it tells me people are actually testing this RC and just not finding problems with it.

If you run into any obvious bugs, please follow "How to file a bug report" - I need logs and reproduction steps to fix issues, not just the information that something doesn't work.

Thanks!

Things to take a closer look at

For this RC, these things should get a closer look while testing, if possible:

  1. proper behaviour when using the included web interface as well as any third party clients at your disposal
  2. printing via a serial connection
  3. managing files on your printer's storage via a serial connection
  4. blocklisted serial ports and/or baud rates are properly migrated to the serial connector (one per line, not comma-separated)
  5. if your printer's disconnected state happens to be "after error", please report back on which connector you used and what the reported error is
  6. if you have a Klipper/Moonraker based printer available: can you use it through OctoPrint when you install the Moonraker Connector?
  7. if you have a Bambu based printer available: can you use it through OctoPrint when you install the Bambu Connector?
✋ Heads-ups

The heads-ups from 2.0.0rc1 still apply!

🔒 Security fixes
  • XSS in Suppressed Command Notifications, severity Moderate (4.6): OctoPrint versions up to and including 1.11.7 as well as 2.0.0rc1 and 2.0.0rc2 are affected by a vulnerability that allows injection of arbitrary HTML and JavaScript into Suppressed Command notifications popups generated by the printer.

    An attacker who successfully convinces a victim to print a specially crafted file could exploit this issue to disrupt ongoing prints, extract information (including sensitive configuration settings, if the targeted user has the necessary permissions for that), or perform other actions on behalf of the targeted user within the OctoPrint instance.

    See also the GitHub Security Advisory and CVE-2026-35163.

  • File exfiltration possible via further parameter injection on upload endpoints, severity High (7.0): OctoPrint versions up until and including 1.11.7 as well as 2.0.0rc1 and 2.0.0rc2 contain a vulnerability that allows an attacker with the FILE_UPLOAD permission to exfiltrate files from the host that OctoPrint has read access to, by moving them into the upload folder where they then can be downloaded from. This vulnerability was already reported as GHSA-m9jh-jf9h-x3h2/CVE-2025-48067 but the fix provided in OctoPrint 1.11.2 turned out to be incomplete.

    The primary risk lies in the potential exfiltration of secrets stored inside OctoPrint's config, or further system files. By removing important runtime files, this could also be used to impact the availability of the host after an attempted server restart. Given that the attacker requires a user account with file upload permissions, the actual impact of this should however hopefully be minimal in most cases.

    See also the GitHub Security Advisory and CVE-2026-54134.

✨ Improvements
Core
  • Added the used printer connector to various printer related events.
Core UI
  • Add support for hiding non-stock marks on the temperature graph.
  • Add "Printing" chart marker: shows start of actual job processing after initial preheating, leveling, etc.
Plugin Manager
  • Add more filter options to the plugin repository browser: It's now possible to filter out any plugins marked as commercial or AI developed.
  • Add display of the ai-developed attribute added on the plugin repository.
🐛 Bug fixes
Core
  • #5404 (regression): Fix "Hide successfully printed files" option in the file list breaking its processing due to JS errors inside the filter.
  • #5419 (regression): Fix /api/job throwing an error in case of a non-int progress.
  • #5421 (regression): Fix crash in Printer.get_current_temperatures when printer connector doesn't support temperature offsets.
  • PR#5422 (regression): Fix download filenames containing a ,
  • (regression) Fix stopping and starting of analysis queue.
  • Update gcode-thumbnail-tool to fix extraction of thumbnails generated by Creality Print 7.x
  • Fix versioning without available tags.
Core UI
  • Ensure temperature graph marks don't wrap.
Gcode Viewer Plugin
  • #5408 (regression): Fix syncing with job progress.
Serial Connector Plugin
  • #5420: Fix thread leak when connecting to a serial port that doesn't respond to the handshake attempts.
🎉 Special thanks to all the contributors!

Special thanks to everyone who contributed to this RC and provided full, analyzable bug reports, especially @jacopotediosi for his PRs!

Also a big thank you to @jacopotediosi and @seankohjs for responsibly disclosing the security vulnerabilities fixed in this release.

🔗 More information
View originalPermalink
How 2.0.0rc3 went

1.11.8

Fixed 1
  • Fix thread leak when connecting to a serial port that doesn't respond to handshake attempts
Security 2
  • Fix XSS vulnerability in Suppressed Command Notifications that allowed injection of arbitrary HTML and JavaScript into notification popups
  • Fix file exfiltration vulnerability on upload endpoints that allowed users with FILE_UPLOAD permission to exfiltrate files from the host
✋ Heads-ups

The heads-ups from previous 1.11.x releases still apply, please read their release notes as well for a full picture of what you should be aware of and what changed!

⛈ Issues while updating?

On every new OctoPrint release we see some people run into the same issues with outdated or broken environments all over again. If you encounter a problem during update, please check this collection of the most common issues encountered over the past couple of release cycles first, and test if the included fixes solve your problem.

♻ Changes
🔒 Security fixes
  • XSS in Suppressed Command Notifications, severity Moderate (4.6): OctoPrint versions up to and including 1.11.7 as well as 2.0.0rc1 and 2.0.0rc2 are affected by a vulnerability that allows injection of arbitrary HTML and JavaScript into Suppressed Command notifications popups generated by the printer.

    An attacker who successfully convinces a victim to print a specially crafted file could exploit this issue to disrupt ongoing prints, extract information (including sensitive configuration settings, if the targeted user has the necessary permissions for that), or perform other actions on behalf of the targeted user within the OctoPrint instance.

    See also the GitHub Security Advisory and CVE-2026-35163.

  • File exfiltration possible via further parameter injection on upload endpoints, severity High (7.0): OctoPrint versions up until and including 1.11.7 as well as 2.0.0rc1 and 2.0.0rc2 contain a vulnerability that allows an attacker with the FILE_UPLOAD permission to exfiltrate files from the host that OctoPrint has read access to, by moving them into the upload folder where they then can be downloaded from. This vulnerability was already reported as GHSA-m9jh-jf9h-x3h2/CVE-2025-48067 but the fix provided in OctoPrint 1.11.2 turned out to be incomplete.

    The primary risk lies in the potential exfiltration of secrets stored inside OctoPrint's config, or further system files. By removing important runtime files, this could also be used to impact the availability of the host after an attempted server restart. Given that the attacker requires a user account with file upload permissions, the actual impact of this should however hopefully be minimal in most cases.

    See also the GitHub Security Advisory and CVE-2026-54134.

🐛 Bug fixes
  • #5420: Fix thread leak when connecting to a serial port that doesn't respond to the handshake attempts.
🎉 Special thanks to all the contributors!

Special thanks to everyone who contributed to this bugfix release, especially @jacopotediosi for his PR!

Also a big thank you to @jacopotediosi and @seankohjs for responsibly disclosing the security vulnerabilities fixed in this release.

🔗 More information
  • Commits
  • Release candidates:
    • As this is a bugfix release, there were no release candidates
View originalPermalink
How 1.11.8 went

2.0.0rc2

Pre-release
Added 5
  • Add option to the sidebar file manager's menu to recursively refresh the current storage's and path's thumbnails if supported
  • Add health check hint for unusable gcode_thumbnail_tool with link to FAQ entry
  • Add support for forgejo_release and forgejo_commit version check types for version checks against Forgejo code forges such as Codeberg
  • Add codeberg_release and codeberg_commit version check types which internally map to forgejo_* with the correct forge parameter
  • Add migration for terminal filters to new filter prefixes
Changed 3
  • Improve migration guide for terminal filters
  • Add more examples to the migration guide and deprecation list
  • Add docs for octoprint.util.version
Fixed 12
  • Fix evaluation of print parameter on upload API
  • Fix deselection of current print job not working
  • Allow None filament weight in /api/job response
  • Gracefully handle unavailability of gcode_thumbnail_tool due to missing OS dependencies
  • Fix file/folder move from root directory
  • Fix file commands on storage root
⚠️ Important note on release candidates

This is a Release Candidate of OctoPrint. It is not a stable release: severe bugs can occur, and they can be bad enough that they make a manual downgrade to an earlier version necessary - maybe even from the command line.

You should be comfortable with and capable of possibly having to do this before installing an RC.

🔁 Feedback on this RC

Please provide general feedback on this RC in this ticket. An "All is working fine" is valuable feedback as well because it tells me people are actually testing this RC and just not finding problems with it.

If you run into any obvious bugs, please follow "How to file a bug report" - I need logs and reproduction steps to fix issues, not just the information that something doesn't work.

Thanks!

Things to take a closer look at

For this RC, these things should get a closer look while testing, if possible:

  1. proper behaviour when using the included web interface as well as any third party clients at your disposal
  2. printing via a serial connection
  3. managing files on your printer's storage via a serial connection
  4. blocklisted serial ports and/or baud rates are properly migrated to the serial connector (one per line, not comma-separated)
  5. if your printer's disconnected state happens to be "after error", please report back on which connector you used and what the reported error is
  6. if you have a Klipper/Moonraker based printer available: can you use it through OctoPrint when you install the Moonraker Connector?
  7. if you have a Bambu based printer available: can you use it through OctoPrint when you install the Bambu Connector?
✋ Heads-ups

The heads-ups from 2.0.0rc1 still apply!

✨ Improvements
Core
  • #5385: Add migration for terminal filters to new filter prefixes. Also improve migration guide accordingly.
Core UI
  • Add option to the sidebar file manager's menu to (recursively) refresh the current storage's & path's thumbnails (if supported).
Healthcheck Plugin
  • Add health check hint for unusable gcode_thumbnail_tool with link to the FAQ entry.
Software Update Plugin
  • Add support for forgejo_release and forgejo_commit version check types, which enable version checks against Forgejo code forges such as Codeberg. For Codeberg specifically, there's also codeberg_release and codeberg_commit which internally gets remapped to forgejo_* with the correct forge parameter.
Docs
  • Add more examples to the migration guide and deprecation list.
  • Add docs for octoprint.util.version.
🐛 Bug fixes
Core
  • #5377 (regression): Fix evaluation of print parameter on upload API.
  • #5379 (regression): Fix deselection of current print job not working.
  • #5380 (regression): Allow None filament weight in /api/job response.
  • #5390 (regression): Gracefully handle unavailability of gcode_thumbnail_tool due to missing OS dependencies.
  • #5393 (regression): Fix file/folder move from root directory.
  • (regression) Fix file commands on storage root.
  • Fix repo file links still pointing to master vs main.
Core UI
  • #5375 (regression): Fix broken availability logic on connection button.
  • #5384 (regression): Fix "Update User" button in access settings.
  • #5386 (regression): Fix some template permission checks broken during removal of deprecated code.
Plugin Manager
  • #5382: Fix support for pip VCS URL schemes as archive URL.
Serial Connector
  • Fix error handling in serial detection. A serial error raised during detection should not cause the whole detection workflow to stop, but rather just switch to the next test option.
Software Update Plugin
  • #5400: Fix default tracked branch for OctoPrint commit tracking, was still pointing to master instead of main.
  • Fix default user for OctoPrint release check, was still pointing to foosel instead of OctoPrint (though was also redirected).
Tracking
  • Fix tracking of printer_connected event if the current connector doesn't send a FirmwareData event (prevented tracking of BambuConnector use).
Docs
  • #5394: Fix an example still referring to a removed function.
🎉 Special thanks to all the contributors!

Special thanks to everyone who contributed to this RC and provided full, analyzable bug reports, especially @jneilliii & @jacopotediosi for their PRs!

🔗 More information
View originalPermalink
How 2.0.0rc2 went

2.0.0rc1

Pre-release
Changed 2
  • OctoPrint now requires Python 3.9 or higher, dropping support for Python 3.7 and 3.8
  • The accessControl.trustedRemoteUser setting has been replaced with a list of trusted authentication proxies that must be configured in accessControl.trustedRemoteUser
Removed 2
  • Numerous long-deprecated methods and endpoints have been removed, affecting third-party plugins and clients
  • Calling octoprint without a subcommand is no longer supported; use octoprint serve to run the server instead
⚠️ Important note on release candidates

This is a Release Candidate of OctoPrint. It is not a stable release: severe bugs can occur, and they can be bad enough that they make a manual downgrade to an earlier version necessary - maybe even from the command line.

You should be comfortable with and capable of possibly having to do this before installing an RC.

[!NOTE] Should you get stuck due to a plugin that got broken by this RC (due to removing deprecated things), remember that you can always access a recovery page at /recovery/ that allows you to restart in safe mode!

🔁 Feedback on this RC

Please provide general feedback on this RC in this ticket. An "All is working fine" is valuable feedback as well because it tells me people are actually testing this RC and just not finding problems with it.

If you run into any obvious bugs, please follow "How to file a bug report" - I need logs and reproduction steps to fix issues, not just the information that something doesn't work.

Thanks!

Things to take a closer look at

For this RC, these things should get a closer look while testing, if possible:

  • proper behaviour when using the included web interface as well as any third party clients at your disposal
  • printing via a serial connection
  • managing files on your printer's storage via a serial connection
  • If you have a Klipper/Moonraker based printer available: can you use it through OctoPrint when you install the Moonraker Connector?
  • If you have a Bambu based printer available: can you use it through OctoPrint when you install the Bambu Connector?
✋ Heads-ups
☝️ OctoPrint 2.0.0 requires Python 3.9+

This release of OctoPrint requires Python 3.9+. Python 3.7 & 3.8, still supported by OctoPrint 1.11.x, are no longer supported. Please also see this FAQ entry on OctoPrint's Python version requirements.

🔐 A new setting is available to configure trusted authentication proxies

So far, if you set accessControl.trustRemoteUser to true in your config.yaml, OctoPrint would trust any incoming X-Remote-User header. That could of course in theory be abused if your OctoPrint instance was reachable directly in addition through your trusted authentication proxy. In OctoPrint 2.0.0, the accessControl.trustedRemoteUser setting has been replaced with a list of trusted authentication proxies. This defaults to empty, but if you had trustedRemoteUser enabled it will get set to your list of configured trusted reverse proxies. OctoPrint will now only accept and evaluate the X-Remote-User header if the request it is seeing came via any of your configured trusted authentication proxies - which must also be among your trusted reverse proxies.

If you are currently using the accessControl.trustedRemoteUser feature in OctoPrint, you will want to check whether your list of trusted reverse proxies is configured correctly & contains your trusted authentication proxy prior to upgrading. And once upgraded, you'll want to limit the list of trusted authentication proxies further to only those of your reverse proxies that actually provide authentication.

🧩 Plugin authors need to check if they are still using any of the now removed deprecated features

OctoPrint has been logging deprecations warnings for some of its APIs, classes and utility methods for years, some of which even for a decade now.

Plenty of plugins have been ignoring these deprecation warnings. With the advent of OctoPrint 2.0.0, most of those long deprecated bits and pieces have however now been removed, and those plugins that have been ignoring deprecations without changes will effectively break.

If you are a plugin author, you NEED to consult this migration guide to check and update your plugin so it continues to work against OctoPrint 2.0.0. You might want to check out this scanner tool by @jacopotediosi that allows you to scan your plugin's source code for any deprecated usages, upcoming issues with 2.0.0 and also packaging related problems.

💥 Breaking changes
  • This release of OctoPrint requires Python 3.9+. Python 3.7 & 3.8, still supported by OctoPrint 1.11.x, are no longer supported. Please also see this FAQ entry on OctoPrint's Python version requirements.
  • A ton of long deprecated methods and endpoints have finally been removed in this release. This should mostly affect third party plugins & the odd client. A migration guide is provided containing a full list of the removals and behaviour changes done, and the necessary steps for plugins to stay compatible.
  • Calling octoprint without a subcommand -- as deprecated for close to a decade now -- is no longer supported. Use octoprint serve to run the server. See octoprint --help for built-in documentation.
✨ Features & improvements
Core
  • OctoPrint 2.0.0 completely revamps the printer communication layer: Connecting to and communicating with a printer is now done through a connector, and connectors can be added by plugins! What used to be old comm layer has now been migrated into the bundled Serial Connector Plugin that supports connecting to printers through a serial connection. And there are already two alternative connectors in the works to open up OctoPrint to other printer ecosystems: the Moonraker Connector Plugin allows connecting to printers that get shipped with Klipper/Moonraker on board, and the Bambu Connector Plugin supports connecting to the (local!) API of printers from Bambu Lab.

    The connection dialog will offer you to select the connector to use, and then allow you to enter (and save!) the necessary connection parameters. OctoPrint then talks to your selected connector to connect to your printer, fetch data from it, send jobs to it and in general control it.

    Through connector plugins, everyone can now add support for new (and possibly even proprietary & reverse engineered) printer interfaces and thus take back control from vendors who'd prefer to keep you locked into their own ecosystems.

  • Together with the changes needed to make connectors possible, printer side storage has been turned into a full blown native storage in OctoPrint's internal file manager, and further storages can also be added through plugins. Together with multi storage support added to the file manager panel and the bundled Upload Manager Plugin, and support for cross storage transfer of files and folders, this makes for new possibilities on how to manage your printables. And the storage support built into the printer connector concept also makes sure all of this works natively with whatever printer connector you use, as long as it has implemented the necessary access methods.

  • Native thumbnail support was also added. A stand-alone gcode-thumbnail-tool has been developed that is now used internally to perform thumbnail extraction on the local storage. And the printer connector interface defines methods that if implemented also support fetching & displaying the thumbnails from files stored inside the printer's storage. The file manager panel and the bundled Upload Manager Plugin have both been adjusted to display any available thumbnails.

  • To give printers (and slicers) more control over print time estimation (it's likely they know best how long something will take!), estimations will now also be fetched from the printer connector, if it supports them. In the case of the bundled Serial Connector Plugin, M73 commands contained in the printed GCODE file will now be used to provide print time estimation basically right from your slicer.

  • As there have been plenty of changes to support the new printer connectors, the first class printer storage, and some other things, OctoPrint now supports API versioning on its HTTP APIs. Clients can specify the API version they require with a custom X-OctoPrint-Api-Version header, specifying the OctoPrint version from which they expect the API behaviour and data model, and OctoPrint will match that accordingly. See also the newly added documentation on API versioning.

  • #5194: Improve the performance of the quite expensive /api/files/<storage>/<path> endpoint.

  • PR#5264: Make OctoPrintClient.setCookie be more robust with regards to input parameters.

  • PR#5320: Support for creating remote users (created through an authentication proxy) without a password instead of a random generated one.

  • PR#5321: Add an (optional) configuration setting of trusted authentication proxies, accessControl.trustedAuthProxies. If trusted authentication proxies (address or range, like trusted reverse proxies) are configured, the chain of trusted involved reverse proxies will be checked for any of the authentication proxies. Only if an authentication proxy was involved in the request will the remote user header then be evaluated. This is an additional security measure.

    This new setting also replaces the existing accessControl.trustRemoteUser setting. An empty list here (the default) corresponds to the former default value of false for accessControl.trustRemoteUser. If you had accessControl.trustRemoteUser set to true, a default list of trusted authentication proxies will be set that matches your configured trusted reverse proxies, effectively matching the previous behaviour.

    See also PR#5334.

  • PR#5355: Setting a new password for users without a configured password (e.g. remote users created through an authentication proxy) will now be possible through the user settings panel, no longer requiring the manual intervention of an admin.

GCODE Viewer Plugin
Virtual Printer Plugin
  • PR#5137: Implement support for M106, M107 and M123
🐛 Bug fixes
Core
  • PR#5139: Provide default implementation for PrinterMixin.get_state_id.
  • PR#5232: Fix settings value preprocessors not getting applied to nested values.
  • PR#5261: Fix error reporting when entering the wrong current password when attempting to change it via Settings > Access Control (vs User Settings).
  • PR#5263: Prevent re-authentication prompt when changing your own password (which already requires you to provider your current password).
  • PR#5271: Fix creation of folders not triggering focus on them.
  • #5279: Detect changes on the remote user header and invalidate the current session if it changes.
  • PR#5287: Fix terminal command history not being properly trimmed.
  • PR#5295: Fix job key used for caching file information in the printer state panel not getting reset on job deselect.
  • PR#5306: Fix handling of installing a plugin with a mismatching python requirement.
  • PR#5316: Disallow cyclic sub grouping, leading to crashes. To explain: It was possible before to make a group a subgroup of itself, which would lead to a recursion bug, requiring manual fixes in OctoPrint's config folder. This is no longer possible.
  • PR#5348: Fix the printer profiles API's behaviour when targetting non-existing printer profile IDs. It now returns 404 Not Found in such a case instead of touching the default printer profile.
  • PR#5252: Fix logs in sockjs.py being filtered twice.
  • PR#5256: Fix built-in print time estimator never using the weighted estimate between statistical data and intelligent data, instead always falling back to the dumb linear estimation.
  • PR#5308: Fix the jog command always being interpreted as relative.
  • PR#5318: Properly escape the user name in the "Uploaded by" string.
  • PR#5320: Fix global API key being reset when a new remote user was created through an authentication proxy.
  • PR#5330: Fix the jsclient function OctoPrintClient.files.upload() not working when the documented userdata parameter was provided.
  • PR#5335: Fix a variable name shadowing built-ins in octoprint.util.json.JsonEncoding
  • PR#5351: Make normalization of booleans more consistent across the code base.
  • PR#5355: Fix the credential check workflow being triggered even for users without a configured password (e.g. remote users created through an authentication proxy).
  • PR#5114, PR#5160, PR#5166, PR#5167, PR#5238, PR#5241, PR#5286, PR#5315, PR#5328, PR#5332, PR#5333, PR#5336, PR#5346: Various minor bug, code, test, typo, wording & deprecation warning fixes all across the code base.
Achievements Plugin
  • Remove a logic error in evaluating cancelled vs failed prints & adjusted related achievement wording. See also PR#5256
Announcements Plugin
  • More sanitizing of incoming feed content to protect against potential XSS attacks through misconfigured feed addresses (see also PR#5338)
Anonymous Usage Plugin
  • PR#5270: Fix tracking of slicer name on slicing_started tracking event.
Discovery Plugin
  • #5203: Make sure the mandatory field modelName is always set on uPnP responses
Serial Connector Plugin (former comm layer)
  • PR#5259: Fix crash on connection when having configured a non existing baudrate option in the baudrate blocklist.
  • PR#5296: Fix chamber temperature not being provided to GCODE scripts template context.
Virtual Printer Plugin
  • PR#5268: Fix crash in virtual printer on receiving G28 E.
🎉 Special thanks to all the contributors!

Special thanks to everyone who contributed to this RC, especially to @Ajimaru, @beelsebob, @bradyjoh, @emmanuel-ferdman, @Hillshum, @jacopotediosi, @jneilliii, @kubedzero and @willschlitzer for their PRs!

And an extra shoutout to our 7 first time contributors: @Ajimaru, @beelsebob, @bradyjoh, @emmanuel-ferdman, @Hillshum, @kubedzero and @willschlitzer! 🎉

🔗 More information
View originalPermalink
How 2.0.0rc1 went

1.11.7

Fixed 8
  • Add custom parser for User Agent under Prusa Slicer's webview, fixing an UI loading error
  • Use the right capability for registering active position autoreporting
  • Fix checkboxes not showing for unrendered timelapses
  • Fix response behaviour on missing subgroups on access management API
  • Don't send session cookies if login mechanism is apikey
  • Correctly convert timezone in Last-Modified
  • Fix help and generated output for octoprint user activate and deactivate commands
  • Fix cleanup tab always staying empty in Plugin Manager
✋ Heads-ups

The heads-ups from previous 1.11.x releases still apply, please read their release notes as well for a full picture of what you should be aware of and what changed!

⛈ Issues while updating?

On every new OctoPrint release we see some people run into the same issues with outdated or broken environments all over again. If you encounter a problem during update, please check this collection of the most common issues encountered over the past couple of release cycles first, and test if the included fixes solve your problem.

♻ Changes
🐛 Bug fixes
Core
  • #5235: Add custom parser for User Agent under Prusa Slicer's webview, fixing an UI loading error
  • #5240: Use the right capability for registering active position autoreporting
  • #5248: Fix checkboxes not showing for unrendered timelapses
  • #5249: Fix response behaviour on missing subgroups on access management API
  • #5250: Don't send session cookies if login mechanism is apikey
  • #5252: Correctly convert timezone in Last-Modified
CLI
  • #5239: Fix help & generated output for octoprint user {activate|deactivate}
Plugin Manager
  • #5254: Fix cleanup tab always staying empty
🎉 Special thanks to all the contributors!

Special thanks to everyone who contributed to this bugfix release, especially to @jacopotediosi for his PRs!

🔗 More information
  • Commits
  • Release candidates:
    • As this is a bugfix release, there were no release candidates
View originalPermalink
How 1.11.7 went

1.11.6

Added 1
  • Support resetting yearly stats and display the status of the current year in Achievements Plugin
Fixed 4
  • Correctly apply preprocessors on settings get and set when handling nested values
  • Properly handle year changes during runtime in stats collection and auto fix stats affected by the underlying issue in Achievements Plugin
  • Fix multi select on MacOS in Upload Manager Plugin to use Cmd+Click
  • Fix shift select logic in Upload Manager Plugin to be more inline with common operating system file explorers
Security 1
  • Fix timing side-channel vulnerability in API key authentication that allowed extraction of API keys through network response time measurement
✋ Heads-ups

The heads-ups from previous 1.11.x releases still apply, please read their release notes as well for a full picture of what you should be aware of and what changed!

⛈ Issues while updating?

On every new OctoPrint release we see some people run into the same issues with outdated or broken environments all over again. If you encounter a problem during update, please check this collection of the most common issues encountered over the past couple of release cycles first, and test if the included fixes solve your problem.

♻ Changes
🔒 Security fixes
  • Timing Side-Channel in API Key Authentication, severity Moderate (6.0): OctoPrint versions up to and including 1.11.5 are affected by a (theoretical) timing attack vulnerability that allows API key extraction over the network.

    Due to using character based comparison that short-circuits on the first mismatched character during API key validation, rather than a cryptographical method with static runtime regardless of the point of mismatch, an attacker with network based access to an affected OctoPrint could extract API keys valid on the instance by measuring the response times of the denied access responses and guess an API key character by character.

    The likelihood of this attack actually working is highly dependent on the network's latency, noise and similar parameters. An actual proof of concept was not achieved so far. Still, as always administrators are advised to not expose their OctoPrint instance on hostile networks, especially not on the public internet!

    See also the GitHub Security Advisory and CVE-2026-23892

✨ Features & improvements
Achievements Plugin
  • #5223: Support resetting the yearly stats & display the status of the current year.
🐛 Bug fixes
Core
  • #5231: Correctly apply preprocessors on settings get & set when handling nested values.
Achievements Plugin
  • #5223: Properly handle year changes during runtime in stats collection, which is also used for the Wrapped Plugin. Auto fix stats affected by the underlying issue.
Upload Manager Plugin
  • #5216: Fix multi select on MacOS, now uses Cmd+Click.
  • #5217: Fix shift select logic to be more inline with common operating system file explorers.
🎉 Special thanks to all the contributors!

Special thanks to everyone who contributed to this bugfix release!

Also a big thank you to @yueyueL for responsibly disclosing the security vulnerability fixed in this release.

🔗 More information
  • Commits
  • Release candidates:
    • As this is a bugfix release, there were no release candidates
View originalPermalink
How 1.11.6 went

1.11.5

Fixed 3
  • Workaround for a regression in Tornado 6.5.x, causing file uploads with non-latin-1 characters in the name to fail
  • Fixed logic error in pure-python fallback of search_through_file helper
  • Apply --no-build-isolation during installation of plugins with legacy packaging
✋ Heads-ups

The heads-ups from previous 1.11.x releases still apply, please read their release notes as well for a full picture of what you should be aware of and what changed!

⛈ Issues while updating?

On every new OctoPrint release we see some people run into the same issues with outdated or broken environments all over again. If you encounter a problem during update, please check this collection of the most common issues encountered over the past couple of release cycles first, and test if the included fixes solve your problem.

♻ Changes
🐛 Bug fixes
Core
  • #5206: Workaround for a regression in Tornado 6.5.x, causing file uploads with non-latin-1 characters in the name to fail.
  • Fixed logic error in pure-python fallback of search_through_file helper
Backup Plugin
  • Apply --no-build-isolation during installation of plugins with legacy packaging
🎉 Special thanks to all the contributors!

Special thanks to everyone who contributed to this bugfix release!

🔗 More information
  • Commits
  • Release candidates:
    • As this is a bugfix release, there were no release candidates
View originalPermalink
How 1.11.5 went

1.11.4

Added 1
  • Plugin Manager and Software Update Plugin now detect legacy setup.py dependencies and add necessary pip parameters for installation to work with pip >= 25.3
Changed 4
  • Improved gcode parser loading performance by removing unused calculations in the Gcode Viewer Plugin
  • Pinned psutil dependency less aggressively after a broken release was pulled by piwheels
  • Pinned click dependency to a version below 8.3 due to breaking changes
  • Pinned markupsafe dependency to <=3.0.2 under Python 3.9 and armv7 due to buggy toml library in Debian Bullseye
Fixed 2
  • Persist cache key used for file metadata in UI to reduce the likelihood of triggering a file data polling loop
  • Trigger the reload overlay when encountering a CSRF error during a server reconnect to fix the Server Offline error when restoring from a backup
Security 2
  • Fixed XSS in Action Commands Notification and Prompt that allowed injection of arbitrary HTML and JavaScript into popups
  • Protected the execution of system commands with a reauthentication request
✋ Heads-ups

The heads-ups from previous 1.11.x releases still apply, please read their release notes as well for a full picture of what you should be aware of and what changed!

⛈ Issues while updating?

On every new OctoPrint release we see some people run into the same issues with outdated or broken environments all over again. If you encounter a problem during update, please check this collection of the most common issues encountered over the past couple of release cycles first, and test if the included fixes solve your problem.

♻ Changes
🔒 Security fixes
  • XSS in Action Commands Notification and Prompt, severity Moderate (4.6): OctoPrint versions up to and including 1.11.3 are affected by a vulnerability that allows injection of arbitrary HTML and JavaScript into Action Commands notification and prompt popups.

    An attacker who successfully convinces a victim to print a specially crafted file could exploit this issue to disrupt ongoing prints, extract information (including sensitive configuration settings, if the targeted user has the necessary permissions for that), or perform other actions on behalf of the targeted user within the OctoPrint instance.

    If popups have been disabled for both Action Command notifications and prompts, this vulnerability does not have an impact.

    See also the GitHub Security Advisory and CVE-2025-64187

Minor security fixes
  • Protected the execution of system commands with a reauthentication request.
✨ Features & improvements
Gcode Viewer Plugin
  • Got rid of some unused calculations in the gcode parser, greatly improving loading performance.
Plugin Manager Plugin & Software Update Plugin
  • #5204: The Plugin Manager and the Software Update Plugin will now detect if they are about to install an OctoPrint plugin that still uses the legacy setup.py that depends on octoprint_setuptools, and add necessary parameters to pip for installation to work even under pip >= 25.3 (specifically --no-build-isolation --use-pep517). This solves errors installing plugins when the pip version in OctoPrint's virtual environment has been upgraded to 25.3 or newer. See also this FAQ item.
🐛 Bug fixes
Core
  • #5193: Persist cache key used for file metadata in UI to reduce the likelihood of triggering a file data polling loop.
  • #5199: Trigger the reload overlay when encountering a CSRF error during a server reconnect. That fixes the "Server Offline" error encountered when restoring from a backup.
  • Pinned the psutil dependency less aggressively again, after a broken release was pulled by piwheels.
  • Pinned the click dependency to a version below 8.3 due to breaking changes. This is a temporary solution for the 1.11.x release in particular, 1.12.0 will ship with full compatibility to current click releases again.
  • Pinned the markupsafe dependency to <=3.0.2 under Python 3.9 and armv7 due to the stock Python 3 environment found on Debian Bullseye that matches these parameters containing a buggy toml library that can no longer parse the packaging file of recent releases.
🎉 Special thanks to all the contributors!

Special thanks to everyone who contributed to this bugfix release!

Also a big thank you to @jacopotediosi for responsibly disclosing the security vulnerability fixed in this release.

🔗 More information
  • Commits
  • Release candidates:
    • As this is a bugfix release, there were no release candidates
View originalPermalink
How 1.11.4 went

1.11.3

Added 3
  • Add new CLI command to trigger the appkey request workflow via octoprint plugin appkeys:request-key
  • Allow configuring whether to enable shell mode on a system event hook in the Event Manager Plugin
  • Add new healthcheck to check for deprecated global API key being set and possibly used, disabled by default and will be enabled with 1.12.0
Changed 2
  • Introduce new shell parameter on type: system commands to explicitly configure whether commands should be run in a shell or directly, currently defaulting to true and changing to false in 1.13.0
  • Event Manager Plugin UI improvements
Fixed 6
  • Fix unwanted side effect on HierarchicalChainMap._unflatten that could make it impossible to reset the run-time value of a dict-based setting back to an empty dict
  • Remove uses of the cgi module which has been deprecated and removed from Python 3.13+
  • Add note that the global API key will be removed with the release of OctoPrint 1.13.0
  • Pin psutil dependency to version 6.0.0 to work around a problem with its builds available on piwheels
  • Fix access request handling on newly opened page in Application Keys Plugin
  • Use proper name for filesViewModel instead of deprecated name gcodeFilesViewModel in Upload Manager Plugin
Deprecated 1
  • Global API key is deprecated and will be removed in OctoPrint 1.13.0, users should switch to Application Keys instead
Security 2
  • Fix RCE in OctoPrint via unsanitized filename in file upload (CVE-2025-58180), a high severity vulnerability allowing authenticated attackers to upload files under specially crafted filenames that could enable arbitrary command execution if included in system event handler commands
  • Remove unused and unneeded cookie setter functionality in LargeResponseHandler that could be used to break returned responses through user input
✋ Heads-ups

The heads-ups from 1.11.0 still apply, please read this release's release notes as well for a full picture of what you should be aware of and what changed!

🔒 Explicitly configure whether to use shell mode for your system event subscriptions

OctoPrint 1.11.3 introduces a new shell parameter on type: system commands that allows to specify whether the command should be run in a shell (true, currently the default) or directly (false, the future default).

Running commands in a shell has security implications as a misconfigured command with placeholders coming from external, potential untrusted sources can lead to arbitrary command execution. However, running commands in a shell also allows for more powerful scripting and also access to the shell’s environment, making it often unnecessary to set the full paths of commands that are supposed to be run.

OctoPrint so far has been running system commands defined in event hooks within a shell. Starting with OctoPrint 1.11.3, OctoPrint will log a message to octoprint.log when it encounters a system hook that hasn’t yet explicitly configured shell, and default to enabling shell mode. From 1.13.0 onward, this behaviour will change, and OctoPrint will default to not enabling shell mode in such cases, to further reduce the attack surface.

You should make an explicit decision now. Try to make your commands work without having to enable shell mode, and thoroughly vet your commands and parameter processing if you have to enable shell mode.

The bundled Event Manager's UI has been adjusted to allow you to configured the shell parameter.

🔥 Switch to Application Keys, the global API key will be removed in 1.13.0

The global API key has been deprecated for a long time now. So far the deprecation notice said it would be removed in OctoPrint 2.0, however this now has been rescheduled to OctoPrint 1.13.0.

OctoPrint 1.12.0 will prepare this removal further and ship with a new health check enabled that will detect if you have a global API key set. OctoPrint 1.13.0 will then remove it altogether.

Instead of using the global key you should create individual Application Keys for your third party clients. That way they get permissions matching the user account used for key creation and you can also revoke access to one app without having to change the keys for all other apps. It's also recommended to create a user account without admin access and use that for third party clients where possible.

⛈ Issues while updating?

On every new OctoPrint release we see some people run into the same issues with outdated or broken environments all over again. If you encounter a problem during update, please check this collection of the most common issues encountered over the past couple of release cycles first, and test if the included fixes solve your problem.

♻ Changes
🔒 Security fixes
  • RCE in OctoPrint via Unsanitized Filename in File Upload, severity High (7.5): OctoPrint versions up until and including 1.11.2 contain a vulnerability that allows an authenticated attacker to upload a file under a specially crafted filename that will allow arbitrary command execution if said filename becomes included in a command defined in a system event handler and said event gets triggered.

    If no event handlers executing system commands with uploaded filenames as parameters have been configured, this vulnerability does not have an impact.

    See also the GitHub Security Advisory and CVE-2025-58180

Minor Security fixes
  • #5169: Got rid of unused and unneeded cookie setter functionality in LargeResponseHandler as it could be used to break returned responses through used input.
✨ Features & improvements
Application Keys Plugin
  • Added a new CLI command to trigger the appkey request workflow, see octoprint plugin appkeys:request-key --help for details.
Event Manager Plugin
  • Allow configuring whether to enable shell mode on a system event hook.
  • Slight UI changes to improve UX.
Healthcheck Plugin
  • New healthcheck to check for deprecated global API key being set and possibly used, disabled for now, will be enabled with 1.12.0
🐛 Bug fixes
Core
  • #5177: Removed an unwanted side effect on HierarchicalChainMap._unflatten that could make it impossible to reset the run-time value of a dict-based setting back to an empty dict.
  • Got rid of any uses of the cgi module, which has been deprecated for a while now and removed from Python 3.13+.
  • Added a note that the global API key will be removed with the release of OctoPrint 1.13.0.
  • Pinned the psutil dependency to version 6.0.0 to work around a problem with its builds available on piwheels.
Application Keys Plugin
  • #5170: Fix access request handling on newly opened page
Upload Manager Plugin
  • Use proper name for filesViewModel instead of deprecated name gcodeFilesViewModel.
🎉 Special thanks to all the contributors!

Special thanks to everyone who contributed to this bugfix release!

Also a big thank you to @prabhatverma47 for responsibly disclosing the security vulnerabilities fixed in this release.

🔗 More information
  • Commits
  • Release candidates:
    • As this is a bugfix release, there were no release candidates
View originalPermalink
How 1.11.3 went
View all

Discussion