Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7.
Metrics
Affected Vendors & Products
References
History
Wed, 04 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7. | |
| Title | Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication | |
| Weaknesses | CWE-306 CWE-321 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2026-02-04T20:06:30.538Z
Updated: 2026-02-04T20:35:30.607Z
Reserved: 2026-02-02T18:21:42.486Z
Link: CVE-2026-25505
Updated: 2026-02-04T20:35:23.575Z
Status : Received
Published: 2026-02-04T20:16:07.707
Modified: 2026-02-04T20:16:07.707
Link: CVE-2026-25505
No data.