Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gc24-px2r-5qmf | Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication |
Fri, 27 Feb 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Bambuddy
Bambuddy bambuddy |
|
| CPEs | cpe:2.3:a:bambuddy:bambuddy:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Bambuddy
Bambuddy bambuddy |
Fri, 06 Feb 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Maziggy
Maziggy bambuddy |
|
| Vendors & Products |
Maziggy
Maziggy bambuddy |
Wed, 04 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7. | |
| Title | Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication | |
| Weaknesses | CWE-306 CWE-321 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-06T18:41:07.205Z
Reserved: 2026-02-02T18:21:42.486Z
Link: CVE-2026-25505
Updated: 2026-02-04T20:35:23.575Z
Status : Analyzed
Published: 2026-02-04T20:16:07.707
Modified: 2026-02-27T20:25:05.510
Link: CVE-2026-25505
No data.
OpenCVE Enrichment
Updated: 2026-04-18T20:15:09Z
Github GHSA