CVE-2025-58762: Tautulli vulnerable to Authenticated Remote Code Execution via write primitive and `Script` notification agent

Published Sep 9, 2025
·
Updated

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. In Tautulli v2.15.3 and earlier, an attacker with administrative access can use the pmsimageproxy endpoint to write arbitrary python scripts into the application filesystem. This leads to remote code execution when combined with the Script notification agent. If an attacker with administrative access changes the URL of the PMS to a server they control, they can then abuse the pmsimageproxy to obtain a file write into the application filesystem. This can be done by making a pmsimageproxy request with a URL in the img parameter and the desired file name in the imgformat parameter. Tautulli then uses a hash of the desired metadata together with the imgformat in order to construct a file path. Since the attacker controls imgformat which occupies the end of the file path, and imgformat is not sanitised, the attacker can then use path traversal characters to specify filename of their choosing. If the specified file does not exist, Tautaulli will then attempt to fetch the image from the configured PMS. Since the attacker controls the PMS, they can return arbitrary content in response to this request, which will then be written into the specified file. An attacker can write an arbitrary python script into a location on the application file system. The attacker can then make use of the built-in Script notification agent to run the local script, obtaining remote code execution on the application server. Users should upgrade to version 2.16.0 to receive a patch.

Affected Software

2 affected components
Tautulli Tautulli<=2.15.3
Tautulli Tautulli<2.16.0

Event History

Sep 9, 2025
CVE Published
via MITRE·08:08 PM
Data Sourced
via MITRE·08:08 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-58762?

CVE-2025-58762 has a critical severity level due to the potential for remote code execution.

2

How do I fix CVE-2025-58762?

To fix CVE-2025-58762, upgrade Tautulli to version 2.15.4 or later.

3

Who is affected by CVE-2025-58762?

CVE-2025-58762 affects users of Tautulli versions 2.15.3 and earlier with administrative access.

4

What type of vulnerability is CVE-2025-58762?

CVE-2025-58762 is a remote code execution vulnerability.

5

Can CVE-2025-58762 be exploited without administrative access?

No, exploitation of CVE-2025-58762 requires administrative access to the Tautulli application.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203