{"id":"CVE-2026-45381","published":"2026-09-21T20:17:25.263","lastModified":"2026-09-21T20:17:25.413","description":"Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to 2.17.2, the /search endpoint inserts its user-controlled query parameter into a JavaScript string in data/interfaces/default/search.html using manual escaping that handles quotes and slashes but not backslashes. A backslash-quote sequence can terminate the string, so an unauthenticated attacker can send a crafted link that executes script in the Tautulli web context when an authenticated user follows it. This issue is fixed in version 2.17.2.","cvssScore":null,"cvssSeverity":null,"cvssVector":null,"cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://github.com/Tautulli/Tautulli/commit/3bee54087370fc275b13565a9e58235341bb4cf7","tags":[]},{"url":"https://github.com/Tautulli/Tautulli/releases/tag/v2.17.2","tags":[]},{"url":"https://github.com/Tautulli/Tautulli/security/advisories/GHSA-mjvc-6cc2-6ffr","tags":[]}],"exploitRefs":[{"url":"https://github.com/Tautulli/Tautulli/commit/3bee54087370fc275b13565a9e58235341bb4cf7","tags":[]},{"url":"https://github.com/Tautulli/Tautulli/releases/tag/v2.17.2","tags":[]},{"url":"https://github.com/Tautulli/Tautulli/security/advisories/GHSA-mjvc-6cc2-6ffr","tags":[]}],"hasPoc":true,"ai":null}