Known CVE
Tautulli <= 2.16.1 - Path Traversal
Tautulli is a monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the `/newsletter/image/images` endpoint joins user-controlled path segments onto the newsletter image directory without containment validation. Authentication is not required for this endpoint, allowing unauthenticated attackers to perform directory traversal and read arbitrary files accessible to the server process. Reading `config/config.ini` discloses the API key, the hashed admin password, the JWT token secret, and the Plex Media Server token. Version 2.17.0 fixes this issue.
CVE-2026-31831
cve2026 · tautulli · lfi · traversal
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website