Tautulli
Monitoring and analytics for Plex media servers
Plex's analytics companion has spent a year shipping CVE fixes faster than features.
◆Recent moves
- 1mo ago
Four CVEs closed: XSS, path traversal and open redirect
The densest security release in the window — XSS in the newsletter cron value and in the search query string, path traversal in uploaded database and config filenames, and an open redirect via whitespace bypass in /auth/redirect, each externally reported. The non-security content is a Gotify line-break fix and duplicated progress timers.
View source ↗ - 3mo ago
RCE via newsletter custom template directory fixed; AV1 and Opus flags added
Another remote code execution path closed in the newsletter templating subsystem, which is the second RCE from that area in three releases. Alongside it, the feature work is modest: AV1 and Opus media flag images, extra notification parameters, and a fix for Tautulli failing to reconnect to Plex after a dropped connection.
View source ↗ - 4mo ago
Python 3.10 now required; RCE in notification text evaluation fixed
The release that raises the minimum Python to 3.10 and closes an RCE in notification text evaluation plus an unauthenticated path traversal in the newsletter image endpoint. The notes lead with an explicit warning that all versions at or below 2.16.1 are vulnerable.
View source ↗ - 4mo ago
Image endpoints validate paths and formats after four CVEs
Four CVEs from a single reporter covering image path and format validation across /image and /pms_image_proxy, plus removing shell invocation from a git command. This is the release that started the current pattern of security-first notes.
View source ↗ - 5mo ago
Plex token expiry alerts and a code editor for newsletter templates
The one release in this window driven by features rather than findings: a notification trigger for expired Plex tokens, an Ace editor with syntax highlighting for newsletter message text, new time formats for home stats and activity cards, and zipped backups. Graphs were also restricted for guest users.
View source ↗ - 1y ago
Config values can now be set via environment variables
Environment-variable configuration is the durable change here — it makes Tautulli materially easier to run as a container without a mounted config file. The rest is exporter attributes for accessibility subtitle and audio tracks, and a fix for collections over 1000 items.
View source ↗