Tautulli
Monitoring and analytics for Plex media servers
Tautulli's release notes read like a security advisory with a changelog attached.
◆Recent moves
- 19d ago
Guest history exposure closed in the API; X-Frame-Options added
A patch release that is mostly fixes — empty session rows written to the database, email passwords blanked on save, new-device notifications retriggering — with one that carries further: guest users could retrieve another user's history through the API. The X-Frame-Options config entry is the only addition, and it is hardening rather than a feature.
View source ↗ - 22d ago
Dolby Atmos support and a push relay replacing OneSignal
Adds Atmos to activity cards and notification parameters, moves history pagination into SQL for performance, and introduces a push relay for Remote App notifications ahead of OneSignal's deprecation in October. Two more CVEs are closed alongside it, keeping the release in the pattern every version here has followed.
View source ↗ - 3mo ago
Four CVEs closed: XSS, path traversal and open redirect
An almost entirely security-driven release covering XSS in newsletter cron values and search query strings, path traversal in uploaded file names, and an open redirect via whitespace bypass. The only functional fixes are cosmetic by comparison.
View source ↗ - 4mo ago
RCE via newsletter custom template directory fixed; AV1 and Opus flags added
Closes a remote code execution path through custom newsletter template directories plus three further CVEs, and moves Windows and macOS packages to Python 3.13. The AV1 and Opus media flags are the visible additions.
View source ↗ - 5mo ago
Python 3.10 now required; RCE in notification text evaluation fixed
Drops Python 3.9, fixes remote code execution in notification text evaluation, SQL injection in get_home_stats and an unauthenticated path traversal, and removes the get_apikey API command. The release note leads with an explicit instruction to upgrade off 2.16.1 and earlier.
View source ↗ - 5mo ago
Image endpoints validate paths and formats after four CVEs
Adds path and format validation to the image and pms_image_proxy endpoints and stops running git through a shell, closing four reported vulnerabilities. The start of the sustained researcher attention visible in every release since.
View source ↗