Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. This issue has been patched in version 2.17.0.
References
| Link | Resource |
|---|---|
| https://github.com/Tautulli/Tautulli/releases/tag/v2.17.0 | Release Notes |
| https://github.com/Tautulli/Tautulli/security/advisories/GHSA-xp55-2pf4-fv8m | Exploit Vendor Advisory |
| https://github.com/Tautulli/Tautulli/security/advisories/GHSA-xp55-2pf4-fv8m | Exploit Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-03-30 20:16
Updated : 2026-06-17 10:34
NVD link : CVE-2026-31831
Mitre link : CVE-2026-31831
CVE.ORG link : CVE-2026-31831
JSON object : View
Products Affected
tautulli
- tautulli
CWE
CWE-23
Relative Path Traversal
