Skip to main content
Vulnerability Database/CVE-2026-45381

CVE-2026-45381: Tautulli XSS Vulnerability

CVE-2026-45381 is a cross-site scripting flaw in Tautulli that allows attackers to execute malicious scripts when authenticated users click crafted links. This article covers technical details, affected versions, and mitigation.

Updated:

CVE-2026-45381 Overview

CVE-2026-45381 is a reflected cross-site scripting (XSS) vulnerability [CWE-79] in Tautulli, a Python-based monitoring and tracking tool for Plex Media Server. The /search endpoint inserts a user-controlled query parameter into a JavaScript string in data/interfaces/default/search.html. The template uses manual escaping that handles quotes and slashes but not backslashes. An attacker can use a backslash-quote sequence to terminate the string and inject arbitrary JavaScript. Exploitation requires an authenticated Tautulli user to follow a crafted link. The issue is fixed in Tautulli version 2.17.2.

Critical Impact

Successful exploitation executes attacker-controlled JavaScript in the Tautulli web context, enabling session theft, configuration tampering, and pivoting into the connected Plex Media Server environment.

Affected Products

  • Tautulli versions prior to 2.17.2
  • Deployments exposing the /search endpoint to authenticated users
  • Any platform running vulnerable Tautulli builds (Docker, Windows, macOS, Linux)

Discovery Timeline

  • 2026-09-21 - CVE-2026-45381 published to NVD
  • 2026-09-21 - Last updated in NVD database
  • Tautulli v2.17.2 - Fix released via Tautulli Release v2.17.2

Technical Details for CVE-2026-45381

Vulnerability Analysis

The vulnerability resides in the Mako template data/interfaces/default/search.html. The template embeds the query request parameter directly into an inline <script> block after applying a manual str.replace chain that escapes only double quotes and forward slashes. Backslashes remain unescaped. An attacker supplies a payload such as \";alert(1)//, where the backslash cancels the escape applied to the following quote, terminating the JavaScript string literal. The remaining input parses as executable JavaScript in the browser of any authenticated Tautulli user who visits the crafted URL.

Root Cause

The root cause is improper output encoding in a JavaScript context. Manual character replacement is insufficient for JavaScript string literal contexts because it does not handle escape-sequence interactions. The fix replaces the ad-hoc escaping with json.dumps, which produces a safely encoded JavaScript literal regardless of the input characters.

Attack Vector

Exploitation is network-based and requires user interaction. An unauthenticated attacker crafts a URL to the vulnerable Tautulli /search endpoint containing the malicious query value. The attacker delivers the link through phishing, chat, or a public web page. When an authenticated Tautulli operator follows the link, the injected script executes with the privileges of the Tautulli web session.

text
// Security patch in data/interfaces/default/search.html
 </%def>
 
 <%def name="javascriptIncludes()">
+<%
+    import json
+%>
 <script>
-    var query_string = "${query.replace('"','\\"').replace('/','\\/') | n}";
+    var query_string = ${json.dumps(query) | n};
 
     $('#query').val(query_string);
     if ($(window).width() >= 768) {

Source: GitHub Commit 3bee5408. The patch replaces manual quote/slash escaping with json.dumps, producing a fully encoded JavaScript string literal.

Detection Methods for CVE-2026-45381

Indicators of Compromise

  • Access log entries for /search containing backslash-quote sequences such as %5C%22 or \" in the query parameter.
  • Requests to /search with query values containing <script>, onerror=, javascript:, or encoded variants.
  • Referrer headers pointing to external, untrusted domains for requests to the Tautulli /search endpoint.
  • Unexpected outbound requests from browsers immediately after visits to /search URLs.

Detection Strategies

  • Inspect Tautulli HTTP access logs for /search?query= parameters containing escape-breaking payloads or HTML/JS metacharacters.
  • Deploy a web application firewall rule that flags backslash-quote patterns and script tags in query string parameters targeting Tautulli.
  • Enable browser Content Security Policy reporting to capture inline script violations originating from Tautulli pages.

Monitoring Recommendations

  • Monitor authentication events, configuration changes, and API key generation in Tautulli that follow abnormal /search traffic.
  • Alert on Tautulli sessions performing sensitive actions immediately after page loads containing suspicious query parameters.
  • Correlate Plex Media Server administrative activity with preceding Tautulli web traffic to identify chained abuse.

How to Mitigate CVE-2026-45381

Immediate Actions Required

  • Upgrade Tautulli to version 2.17.2 or later using the official Tautulli Release v2.17.2.
  • Restrict Tautulli web interface exposure to trusted networks or place it behind an authenticating reverse proxy.
  • Rotate Tautulli API keys and force session re-authentication if suspicious /search traffic is observed.
  • Review the GitHub Security Advisory GHSA-mjvc-6cc2-6ffr for the vendor's guidance.

Patch Information

The fix is included in Tautulli 2.17.2. Commit 3bee5408 replaces the manual escaping in data/interfaces/default/search.html with json.dumps, ensuring the query value is serialized as a safe JavaScript string literal.

Workarounds

  • Block or filter requests to /search that contain backslash characters or HTML/JS metacharacters at an upstream proxy or WAF.
  • Enforce a strict Content Security Policy that disallows inline scripts to reduce the impact of reflected payloads.
  • Instruct authenticated Tautulli users to avoid clicking untrusted links targeting the Tautulli host until patched.
bash
# Example nginx rule to drop suspicious /search queries until patched
location /search {
    if ($args ~* "(\\|%5C|<script|onerror=|javascript:)") {
        return 403;
    }
    proxy_pass http://tautulli_upstream;
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.