Executive brief
Tautulli is a monitoring tool for Plex Media Server that tracks playback and user activity. An attacker can craft a malicious link to the search feature that executes JavaScript code in the context of any authenticated user who clicks it, potentially allowing account takeover, data theft, or unauthorized actions on the Plex server.
Technical details
The /search endpoint fails to properly escape backslashes in user-supplied query parameters before inserting them into JavaScript string context in search.html. An attacker can inject a backslash-quote sequence to break out of the string and inject arbitrary JavaScript, which executes in the browser of any authenticated user who follows a crafted link. The vulnerability requires user interaction (clicking a link) but does not require authentication from the attacker.
Affected products
- Tautulli Tautulli prior to 2.17.2
Timeline
- 2026-06-16: disclosed
- 2026-06-16: patched: Fixed in version 2.17.2