Junglewise Threat Intelligence

CVE-2026-45381: Tautulli reflected XSS in search query

CVE-2026-45381 · Severity: info · Published 2026-09-21

Technologies: Tautulli. Vendors: Tautulli.

Executive brief

Tautulli is a monitoring tool for Plex Media Server that tracks playback and user activity. An attacker can craft a malicious link to the search feature that executes JavaScript code in the context of any authenticated user who clicks it, potentially allowing account takeover, data theft, or unauthorized actions on the Plex server.

Technical details

The /search endpoint fails to properly escape backslashes in user-supplied query parameters before inserting them into JavaScript string context in search.html. An attacker can inject a backslash-quote sequence to break out of the string and inject arbitrary JavaScript, which executes in the browser of any authenticated user who follows a crafted link. The vulnerability requires user interaction (clicking a link) but does not require authentication from the attacker.

Affected products

  • Tautulli Tautulli prior to 2.17.2

Timeline

  • 2026-06-16: disclosed
  • 2026-06-16: patched: Fixed in version 2.17.2

References

Related threats