Junglewise Threat Intelligence

CVE-2026-43984: Tautulli stored XSS in logFile via log_js_errors

CVE-2026-43984 · Severity: high · CVSS 8.9 · Published 2026-06-04

Technologies: Tautulli. Vendors: Tautulli.

Executive brief

Tautulli, a monitoring tool for Plex Media Servers, contains a security flaw that allows guest users to inject malicious code into the system's activity logs. If an administrator later views these logs through the web interface, the injected code executes in their browser. This could allow a low-privileged user to hijack administrative sessions, steal sensitive data, or perform unauthorized actions on the server.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Tautulli's `log_js_errors` endpoint. This endpoint is accessible to any authenticated user, including guests, and writes user-provided strings directly into the application log file without sanitization. The administrative `logFile` view subsequently reads this log and renders it within a `<pre>` tag in an HTML response without proper escaping. An attacker can exploit this by submitting a crafted JavaScript payload to the error logging endpoint; the payload executes in the context of an administrator's session when they view the logs. This vulnerability is patched in version 2.17.1.

Affected products

  • Tautulli Tautulli < 2.17.1

Timeline

  • 2026-05-04: patched: Version 2.17.1 released
  • 2026-05-27: advisory: GitHub Security Advisory published
  • 2026-06-04: disclosed: NVD publication date

References

Related threats