CVE-2026-31831

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. This issue has been patched in version 2.17.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:tautulli:tautulli:*:*:*:*:*:*:*:*

History

02 Apr 2026, 15:42

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Tautulli tautulli
Tautulli
References () https://github.com/Tautulli/Tautulli/releases/tag/v2.17.0 - () https://github.com/Tautulli/Tautulli/releases/tag/v2.17.0 - Release Notes
References () https://github.com/Tautulli/Tautulli/security/advisories/GHSA-xp55-2pf4-fv8m - () https://github.com/Tautulli/Tautulli/security/advisories/GHSA-xp55-2pf4-fv8m - Exploit, Vendor Advisory
CPE cpe:2.3:a:tautulli:tautulli:*:*:*:*:*:*:*:*

31 Mar 2026, 20:16

Type Values Removed Values Added
Summary
  • (es) Tautulli es una herramienta de monitoreo y seguimiento basada en Python para Plex Media Server. Antes de la versión 2.17.0, el endpoint de la API /newsletter/image/images es vulnerable a salto de ruta, permitiendo a atacantes no autenticados leer archivos arbitrarios del sistema de archivos del servidor de aplicaciones. Este problema ha sido parcheado en la versión 2.17.0.
References () https://github.com/Tautulli/Tautulli/security/advisories/GHSA-xp55-2pf4-fv8m - () https://github.com/Tautulli/Tautulli/security/advisories/GHSA-xp55-2pf4-fv8m -

30 Mar 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-30 20:16

Updated : 2026-04-02 15:42


NVD link : CVE-2026-31831

Mitre link : CVE-2026-31831

CVE.ORG link : CVE-2026-31831


JSON object : View

Products Affected

tautulli

  • tautulli
CWE
CWE-23

Relative Path Traversal