Path Traversal Vulnerability in Tautulli for Plex Media Server
CVE-2025-58761
What is CVE-2025-58761?
Tautulli, a monitoring tool for Plex Media Server, is prone to a path traversal vulnerability affecting versions up to 2.15.3. This flaw allows unauthenticated attackers to exploit the real_pms_image_proxy endpoint by passing manipulated img URL parameters. By circumventing file path restrictions, attackers can access sensitive files on the application server, including critical configuration files and the SQLite database that stores active JWT tokens and hashed passwords. If an attacker retrieves valid credentials, they may gain administrative privileges and take control of the Tautulli application. An important update is available in version 2.16.0 which addresses this security issue.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Tautulli < 2.16.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
