Executive brief
Tautulli is a monitoring and tracking tool for Plex Media Server that allows administrators to manage configurations and databases. Prior to version 2.17.2, an authenticated administrator with the API key could upload files with specially crafted names containing path traversal sequences (../) to write files outside the intended cache directory, potentially allowing them to tamper with configuration, disrupt the service, or achieve code execution.
Technical details
The vulnerability exists in the import_config and import_database handlers in plexpy/webserve.py, which join attacker-controlled multipart upload filenames directly to CACHE_DIR without canonicalization (basename reduction) or containment checks. An authenticated caller can submit filenames with ../ segments to write outside the intended directory. The write scope is limited to paths the Tautulli process has permission to access, but the lack of filename sanitization before joining enables arbitrary file creation or overwrite within process permissions. Fixed in 2.17.2 by applying os.path.basename to reduce filenames before joining.
Affected products
- Tautulli Tautulli before 2.17.2
Timeline
- 2026-06-16: disclosed: Fixed in version 2.17.2
- 2026-09-21: advisory