๐Ÿ” CVE Alert

CVE-2026-31831

UNKNOWN 0.0

Tautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint

CVSS Score
0.0
EPSS Score
0.1%
EPSS Percentile
26th

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the /newsletter/image/images API endpoint is vulnerable to path traversal, allowing unauthenticated attackers to read arbitrary files from the application server's filesystem. This issue has been patched in version 2.17.0.

CWE CWE-23
Vendor tautulli
Product tautulli
Published Mar 30, 2026
Last Updated Mar 31, 2026
Stay Ahead of the Next One

Get instant alerts for tautulli tautulli

Be the first to know when new unknown vulnerabilities affecting tautulli tautulli are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Tautulli / Tautulli
< 2.17.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Tautulli/Tautulli/security/advisories/GHSA-xp55-2pf4-fv8m github.com: https://github.com/Tautulli/Tautulli/releases/tag/v2.17.0