PT-2026-96231 · Tautulli · Tautulli
CVE-2026-54915
·
Published
2026-09-21
·
Updated
2026-09-21
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Tautulli versions prior to 2.17.2
Description
The unauthenticated '/auth/redirect' endpoint in
plexpy/webauth.py fails to properly sanitize the redirect uri parameter. While forward slashes are removed, tab, line-feed, and carriage-return characters remain. When using the default root HTTP ROOT configuration, CherryPy HTTPRedirect passes this value to urllib.parse.urljoin, allowing the whitespace characters to resolve the path to an external origin controlled by an attacker. This can lead to phishing or post-login redirect-flow abuse if a user follows a crafted link. Custom non-root HTTP ROOT configurations are not affected.Recommendations
Update to version 2.17.2.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tautulli