Only the latest released version of bambu receives security fixes. Please upgrade (brew upgrade bambu or
go install the latest tag) before reporting.
Please report security issues privately — do not open a public issue.
- Preferred: GitHub's private vulnerability reporting (the "Report a vulnerability" button on the repository's Security tab).
We aim to acknowledge reports within 5 business days and to ship a fix or mitigation for confirmed issues as quickly as is practical, crediting reporters who wish to be named.
bambu controls a machine that heats to 300 °C, so:
- The printer's LAN access code is stored in the OS keychain (service
bambu, account = serial). It is never printed, logged or written to the config file.BAMBU_ACCESS_CODEexists for CI/headless use — keep it out of shell history and shared logs. - The code is passed to
ffmpegin the RTSPS URL for camera snapshots and is therefore briefly visible to local process listings; errors are redacted. - Printers use self-signed TLS certificates, so
bambudoes not verify them. Only use it on networks you trust. print send,print pause|resume|stoprequire--confirm;print sendalso requires a passing preflight.bambunever changes printer settings. Never let an agent pass--confirmwithout a human's approval.