Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gc24-px2r-5qmf | Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 06 Feb 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 05 Feb 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Maziggy
Maziggy bambuddy |
|
| Vendors & Products |
Maziggy
Maziggy bambuddy |
Wed, 04 Feb 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source code and ManyAPI routes do not check authentication. This issue has been patched in version 0.1.7. | |
| Title | Bambuddy Uses Hardcoded Secret Key + Many API Endpoints do not Require Authentication | |
| Weaknesses | CWE-306 CWE-321 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-06T18:41:07.205Z
Reserved: 2026-02-02T18:21:42.486Z
Link: CVE-2026-25505
Updated: 2026-02-04T20:35:23.575Z
Status : Awaiting Analysis
Published: 2026-02-04T20:16:07.707
Modified: 2026-02-06T19:16:09.483
Link: CVE-2026-25505
No data.
OpenCVE Enrichment
Updated: 2026-02-05T11:39:31Z
Github GHSA