critical CVSS 9.1

CVE-2025-58762·Python vulnerability

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attacker with administrative access can use the `pms_image_proxy` endpoint to write arbitrary python scripts into the application filesystem. This leads to remote code execution when combined with the `Script` notification agent. If an attacker with administrative access changes the URL of the PMS to a server they control, they can then abuse the `pms_image_proxy` to obtain a file write into the application filesystem. This can be done by making a `pms_image_proxy` request with a URL in the `img` parameter and the desired file name in the `img_format` parameter. Tautulli then uses a hash of the desired metadata together with the `img_format` in order to construct a file path. Since the attacker controls `img_format` which occupies the end of the file path, and `img_format` is not sanitised, the attacker can then use path traversal characters to specify filename of their choosing. If the specified file does not exist, Tautaulli will then attempt to fetch the image from the configured PMS. Since the attacker controls the PMS, they can return arbitrary content in response to this request, which will then be written into the specified file. An attacker can write an arbitrary python script into a location on the application file system. The attacker can then make use of the built-in `Script` notification agent to run the local script, obtaining remote code execution on the application server. Users should upgrade to version 2.16.0 to receive a patch.

Severity
critical
Software
Python
Fixed in
2.16.0
Published
2025-09-09

Affected versions

Until: 2.16.0

Fixed in: 2.16.0

How to fix this CVE

Upgrade Tautulli to version 2.16.0 or later immediately, as this release patches a critical file write vulnerability in the pms_image_proxy endpoint. The vulnerability allows authenticated administrators to write arbitrary Python scripts to the filesystem and execute them via the Script notification agent, resulting in complete system compromise. Disable or restrict administrative access until the patch is applied, and review PMS server configuration to ensure it points only to legitimate Plex Media Server instances.

sudo dnf update tautulli

Defensia detects this vulnerability

What an exploitation attempt looks like

Sample log line indicative of exploitation attempts:

POST|GET /pms_image_proxy.*img_format=.*(\.\./|%2e%2e|\\x2e\\x2e).*\.(py|pyw|pyc)$ — Look for requests containing path traversal sequences in the img_format parameter targeting Python script file extensions.

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Implement a WAF rule that blocks all requests to /pms_image_proxy where the img_format parameter contains path traversal sequences (../, %2e%2e, \x2e\x2e, or backslash variations). Additionally, restrict access to this endpoint to trusted internal networks only and require re-authentication before accessing admin functions.

How to check if you are affected

  1. Check installed Tautulli version: grep -i 'version' /opt/Tautulli/version.txt || python3 -c "import tautulli; print(tautulli.__version__)" 2>/dev/null
  2. Verify pms_image_proxy endpoint accessibility: curl -s http://localhost:8181/pms_image_proxy?img=test&img_format=jpg | head -20
  3. Search Tautulli logs for suspicious pms_image_proxy requests with path traversal: grep -i 'pms_image_proxy' /var/log/tautulli/tautulli.log | grep -E '(\.\./|\\x2e\\x2e|%2e%2e)'
  4. Verify the update applied: grep -i 'version' /opt/Tautulli/version.txt | grep -E '2\.16\.[0-9]|2\.[2-9][0-9]|[3-9]\.[0-9]'

FAQ

What is CVE-2025-58762?

CVE-2025-58762 is a critical vulnerability in Tautulli that allows authenticated administrators to bypass input validation in the pms_image_proxy endpoint, write malicious Python scripts to the server filesystem using path traversal, and execute arbitrary code through the Script notification agent.

Is CVE-2025-58762 being actively exploited?

No, this vulnerability is not currently listed as actively exploited in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploits have been released, but the attack requires only administrative credentials and is trivial to execute.

What versions of Tautulli are affected by CVE-2025-58762?

All versions of Tautulli up to and including v2.15.3 are vulnerable. The issue is patched in version 2.16.0 and later.

How do I check if my server is vulnerable to CVE-2025-58762?

Run: grep -i 'version' /opt/Tautulli/version.txt — if the version is 2.15.3 or earlier, your installation is vulnerable and requires immediate patching.

Does Defensia detect CVE-2025-58762?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Tautulli is installed on a monitored server, CVE-2025-58762 will appear in your dashboard with remediation steps.

Related Python CVEs

CVE-2026-33054CVSS 10Mesop is a Python-based UI framework that allows users to build web applications. Versions 1.2.2 and below contain a Path Traversal vulnerability that allows any user supplying an untrusted state_token through the UI stream payload to arbitrarily target files on the disk under the standard file-based runtime backend. This can result in application denial of service (via crash loops when reading non-msgpack target files as configurations), or arbitrary file manipulation. This vulnerability heavily exposes systems hosted utilizing FileStateSessionBackend. Unauthorized malicious actors could interact with arbitrary payloads overwriting or explicitly removing underlying service resources natively outside the application bounds. This issue has been fixed in version 1.2.3.
CVE-2026-28505CVSS 10Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.0, the str_eval() function in notification_handler.py implements a sandboxed eval() for notification text templates. The sandbox attempts to restrict callable names by inspecting code.co_names of the compiled code object. However, co_names only contains names from the outer code object. When a lambda expression is used, it creates a nested code object whose attribute accesses are stored in code.co_consts, NOT in code.co_names. The sandbox never inspects nested code objects. This issue has been patched in version 2.17.0.
CVE-2026-34938CVSS 10PraisonAI is a multi-agent teams system. Prior to version 1.5.90, execute_code() in praisonai-agents runs attacker-controlled Python inside a three-layer sandbox that can be fully bypassed by passing a str subclass with an overridden startswith() method to the _safe_getattr wrapper, achieving arbitrary OS command execution on the host. This issue has been patched in version 1.5.90.
CVE-2026-25632CVSS 10EPyT-Flow is a Python package designed for the easy generation of hydraulic and water quality scenario data of water distribution networks. Prior to 0.16.1, EPyT-Flow’s REST API parses attacker-controlled JSON request bodies using a custom deserializer (my_load_from_json) that supports a type field. When type is present, the deserializer dynamically imports an attacker-specified module/class and instantiates it with attacker-supplied arguments. This allows invoking dangerous classes such as subprocess.Popen, which can lead to OS command execution during JSON parsing. This also affects the loading of JSON files. This vulnerability is fixed in 0.16.1.
CVE-2026-9135CVSS 9.9IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_components=false security control. The vulnerability exists because the validation mechanism only checks the main component source code in node_template["code"]["value"] but fails to validate dynamic CodeInput fields that store generated ToolGuard Python files. Attackers can embed malicious Python code in these unvalidated dynamic fields, which are persisted in Flow.data and later executed server-side when a guarded tool is invoked through the ToolGuard runtime. This allows authenticated users with flow creation privileges to achieve arbitrary Python code execution on the backend despite custom component restrictions. The vulnerability can be escalated through cross-tenant flow manipulation via the agentic MCP update_flow_component_field tool, which accepts attacker-controlled user_id parameters, enabling attackers to inject malicious code into victim users' flows. When combined with publicly accessible flows and specific misconfigurations (AUTO_LOGIN=true, NEW_USER_IS_ACTIVE=true), the attack can be conducted with reduced authentication requirements.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-58762. Free for 1 server.

Get started free