CVE-2025-58761 is a path traversal vulnerability in Tautulli v2.15.3 and earlier, a monitoring tool for Plex Media Server. An unauthenticated attacker can exploit the real_pms_image_proxy endpoint to read arbitrary files from the application server's filesystem, bypassing validation by combining a valid prefix with path traversal characters. This high-severity vulnerability (CVSS 7.5) allows for exfiltration of sensitive data like the tautulli.db and config.ini files, potentially leading to administrative control over the application. There is currently no known active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.16.0CPE matchmatch criteria | cpe:2.3:a:tautulli:tautulli:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.