Executive brief
Tautulli, a monitoring tool for Plex Media Server, contains a security flaw in its cache management system. An authorized user or an attacker with an API key can exploit this to delete important folders on the server hosting the application. This could lead to significant data loss, system instability, or a complete shutdown of the monitoring service.
Technical details
A path traversal vulnerability (CWE-22) exists in the Tautulli API's 'delete_cache' command. The 'folder' parameter is used in an 'os.path.join' operation without sufficient validation, allowing an attacker to use '../' sequences to escape the intended cache directory. An authenticated attacker with a valid API key can send a crafted GET request to delete arbitrary directories that the Tautulli process has permissions to modify. This vulnerability was addressed in version 2.17.1 by implementing proper path validation.
Affected products
- Tautulli Tautulli < 2.17.1
Timeline
- 2026-05-04: patched: Version 2.17.1 released
- 2026-05-27: advisory: GitHub Security Advisory published
- 2026-06-04: disclosed: NVD publication date