CVE-2025-58762·Python vulnerability
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attacker with administrative access can use the `pms_image_proxy` endpoint to write arbitrary python scripts into the application filesystem. This leads to remote code execution when combined with the `Script` notification agent. If an attacker with administrative access changes the URL of the PMS to a server they control, they can then abuse the `pms_image_proxy` to obtain a file write into the application filesystem. This can be done by making a `pms_image_proxy` request with a URL in the `img` parameter and the desired file name in the `img_format` parameter. Tautulli then uses a hash of the desired metadata together with the `img_format` in order to construct a file path. Since the attacker controls `img_format` which occupies the end of the file path, and `img_format` is not sanitised, the attacker can then use path traversal characters to specify filename of their choosing. If the specified file does not exist, Tautaulli will then attempt to fetch the image from the configured PMS. Since the attacker controls the PMS, they can return arbitrary content in response to this request, which will then be written into the specified file. An attacker can write an arbitrary python script into a location on the application file system. The attacker can then make use of the built-in `Script` notification agent to run the local script, obtaining remote code execution on the application server. Users should upgrade to version 2.16.0 to receive a patch.
- Severity
- critical
- Software
- Python
- Fixed in
- 2.16.0
- Published
- 2025-09-09
Affected versions
Until: 2.16.0
Fixed in: 2.16.0
How to fix this CVE
Upgrade Tautulli to version 2.16.0 or later immediately, as this release patches a critical file write vulnerability in the pms_image_proxy endpoint. The vulnerability allows authenticated administrators to write arbitrary Python scripts to the filesystem and execute them via the Script notification agent, resulting in complete system compromise. Disable or restrict administrative access until the patch is applied, and review PMS server configuration to ensure it points only to legitimate Plex Media Server instances.
sudo dnf update tautulliDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|GET /pms_image_proxy.*img_format=.*(\.\./|%2e%2e|\\x2e\\x2e).*\.(py|pyw|pyc)$ — Look for requests containing path traversal sequences in the img_format parameter targeting Python script file extensions.WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement a WAF rule that blocks all requests to /pms_image_proxy where the img_format parameter contains path traversal sequences (../, %2e%2e, \x2e\x2e, or backslash variations). Additionally, restrict access to this endpoint to trusted internal networks only and require re-authentication before accessing admin functions.How to check if you are affected
- Check installed Tautulli version: grep -i 'version' /opt/Tautulli/version.txt || python3 -c "import tautulli; print(tautulli.__version__)" 2>/dev/null
- Verify pms_image_proxy endpoint accessibility: curl -s http://localhost:8181/pms_image_proxy?img=test&img_format=jpg | head -20
- Search Tautulli logs for suspicious pms_image_proxy requests with path traversal: grep -i 'pms_image_proxy' /var/log/tautulli/tautulli.log | grep -E '(\.\./|\\x2e\\x2e|%2e%2e)'
- Verify the update applied: grep -i 'version' /opt/Tautulli/version.txt | grep -E '2\.16\.[0-9]|2\.[2-9][0-9]|[3-9]\.[0-9]'
FAQ
What is CVE-2025-58762?
CVE-2025-58762 is a critical vulnerability in Tautulli that allows authenticated administrators to bypass input validation in the pms_image_proxy endpoint, write malicious Python scripts to the server filesystem using path traversal, and execute arbitrary code through the Script notification agent.
Is CVE-2025-58762 being actively exploited?
No, this vulnerability is not currently listed as actively exploited in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public exploits have been released, but the attack requires only administrative credentials and is trivial to execute.
What versions of Tautulli are affected by CVE-2025-58762?
All versions of Tautulli up to and including v2.15.3 are vulnerable. The issue is patched in version 2.16.0 and later.
How do I check if my server is vulnerable to CVE-2025-58762?
Run: grep -i 'version' /opt/Tautulli/version.txt — if the version is 2.15.3 or earlier, your installation is vulnerable and requires immediate patching.
Does Defensia detect CVE-2025-58762?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If Tautulli is installed on a monitored server, CVE-2025-58762 will appear in your dashboard with remediation steps.
Related Python CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-58762. Free for 1 server.
Get started free