Bambuddy offers a narrowly scoped product line centered on its primary application, where the observed vulnerability profile reflects foundational security-control gaps including missing authentication for critical functions and use of hard-coded cryptographic keys. These weaknesses point to design-stage oversights rather than isolated implementation issues, and defenders should prioritize verification of access controls and credential management in deployments. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bambuddy over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25505CRITICAL Bambuddy is a self-hosted print archive and management system for Bambu Lab 3D printers. Prior to version 0.1.7, a hardcoded secret key used for signing JWTs is checked into source | Feb 4, 2026 | 9.8 | 32 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bambuddy.
Media articles that mention a CVE ID that affects a product developed by Bambuddy — matched by CVE ID, not by vendor name.