CVE-2026-45381
Tautulli: Reflected XSS in `/search` endpoint
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter into a JavaScript string in data/interfaces/default/search.html using manual escaping that handles quotes and slashes but not backslashes. A backslash-quote sequence can terminate the string, so an unauthenticated attacker can send a crafted link that executes script in the Tautulli web context when an authenticated user follows it. This issue is fixed in version 2.17.2.
| CWE | CWE-79 |
| Vendor | tautulli |
| Product | tautulli |
| Published | Sep 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for tautulli tautulli
Be the first to know when new unknown vulnerabilities affecting tautulli tautulli are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Tautulli / Tautulli
< 2.17.2