Prusa3d's vulnerability footprint centers on PrusaSlicer, a widely adopted open-source 3D-printing slicing software that translates digital models into printer-executable instructions. The recurring exposure reflects the product's dual role as a file processor and system utility: memory-safety issues such as buffer overflows and out-of-bounds writes, alongside code-integrity and command-injection risks arising from external file handling and plugin/update mechanisms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Prusa3d over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-27438HIGH Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerabil | Jun 6, 2022 | 8.1 | 29 | NO | NO |
CVE-2020-28594HIGH A use-after-free vulnerability exists in the _3MF_Importer::_handle_end_model() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted | Aug 17, 2021 | 7.8 | 25 | NO | NO |
CVE-2020-28596HIGH A stack-based buffer overflow vulnerability exists in the Objparser::objparse() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted | Feb 10, 2021 | 7.8 | 25 | NO | NO |
CVE-2023-47268MEDIUM In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the project is sliced and G-code expo | May 8, 2026 | 5.3 | 24 | NO | NO |
CVE-2020-28598HIGH An out-of-bounds write vulnerability exists in the Admesh stl_fix_normal_directions() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially c | Jul 8, 2021 | 7.8 | 24 | NO | NO |
CVE-2020-28595HIGH An out-of-bounds write vulnerability exists in the Obj.cpp load_obj() functionality of Prusa Research PrusaSlicer 2.2.0 and Master (commit 4b040b856). A specially crafted obj file | Feb 10, 2021 | 7.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Prusa3d.
Media articles that mention a CVE ID that affects a product developed by Prusa3d — matched by CVE ID, not by vendor name.