Executive brief
Tautulli is a monitoring tool for Plex Media Server that tracks playback and usage. An unauthenticated endpoint fails to properly validate redirect URLs, allowing an attacker to craft malicious links that redirect users to external phishing sites or abusive login-flow pages after they follow the attacker's link.
Technical details
The /auth/redirect endpoint in plexpy/webauth.py strips forward slashes from the user-controlled redirect_uri parameter but fails to remove tab, line-feed, and carriage-return characters. When CherryPy's HTTPRedirect passes this malformed URL to urllib.parse.urljoin, whitespace characters allow the path to resolve to an external attacker-controlled origin. The endpoint accepts unauthenticated requests with default HTTP_ROOT configuration; custom non-root configurations are unaffected.
Affected products
- Tautulli Tautulli before 2.17.2
Timeline
- 2026-09-21: disclosed
- 2026-06-16: patched: Fix released in v2.17.2