๐Ÿ” CVE Alert

CVE-2026-32275

CRITICAL 9.1

Tautulli: Unsanitized JSONP callback parameter allows cross-origin script injection and API key theft

CVSS Score
9.1
EPSS Score
0.0%
EPSS Percentile
15th

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. From version 1.3.10 to before version 2.17.0, an unsanitized JSONP callback parameter allows cross-origin script injection and API key theft. This issue has been patched in version 2.17.0.

CWE CWE-79
Vendor tautulli
Product tautulli
Published Mar 30, 2026
Last Updated Apr 1, 2026
Stay Ahead of the Next One

Get instant alerts for tautulli tautulli

Be the first to know when new critical vulnerabilities affecting tautulli tautulli are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Tautulli / Tautulli
>= 1.3.10, < 2.17.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/Tautulli/Tautulli/security/advisories/GHSA-95mg-wpqw-9qxh github.com: https://github.com/Tautulli/Tautulli/releases/tag/v2.17.0