MEDIUM 5.1 NVD
CVE-2026-45381
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter into a JavaScript string in data/interfaces/default/search.html using manual escaping that handles quotes and slashes but not backslashes. A backslash-quote sequence can terminate the string, so an unauthenticated attacker can send a crafted link that executes script in the Tautulli web context when an authenticated user follows it. This issue is fixed in version 2.17.2.
References
- https://github.com/Tautulli/Tautulli/commit/3bee54087370fc275b13565a9e58235341bb4cf7
- https://github.com/Tautulli/Tautulli/releases/tag/v2.17.2
- https://github.com/Tautulli/Tautulli/security/advisories/GHSA-mjvc-6cc2-6ffr
This medium severity vulnerability with a CVSS score of 5.1 was published on 2026-09-21 via NVD.
vulnfeed aggregates 14328 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.