# Tautulli changelog > Monitors a Plex Media Server and reports on what is being watched. - Vendor: Tautulli - Category: Media - Platforms: Desktop - Official site: https://tautulli.com - Tracked by: What's New (https://whatsnew.fyi/product/tautulli) - Harvested from: GitHub (Tautulli/Tautulli) - Entries below: 10 (newest first) What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. ## Releases ### v2.17.2 — Tautulli v2.17.2 - Date: 2026-06-16 - Version: v2.17.2 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.17.2 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.17.2 - Labels: Platforms: Desktop - **fixed** — Line breaks in Gotify notification body text - **security** — XSS in newsletter cron value (CVE-2026-49995) - **security** — Reflected XSS in search query string (CVE-2026-45381) - **fixed** — Duplicated activity card progress timers - **fixed** — X-Api-Key header check crashing server - **security** — Path traversal in uploaded database and config file names (CVE-2026-52835) - **fixed** — Empty host fallback in URL when launching browser - **security** — Open redirect via whitespace bypass in /auth/redirect (CVE-2026-54915) ##### Changelog ###### v2.17.2 (2026-06-16) * Notifications: * Fix: Line breaks in Gotify notification body text. (#2702) * Newsletters: * Fix: XSS in newsletter cron value. (CVE-2026-49995) (Thanks @elvinsuleymanov) * UI: * Fix: Reflected XSS in search query string. (CVE-2026-45381) (Thanks @JakePeralta7, @sondt99, @kah-ja) * Fix: Duplicated activity card progress timers. (#2716) (Thanks @omglazrgunpewpew) * Other: * Fix: Fix X-Api-Key header check crashing server. (#2711) * Fix: Path traversal in uploaded database and config file names. (CVE-2026-52835) (Thanks @tonghuaroot) * Fix: Empty host fallback in URL when launching browser. (#2722) (Thanks @upmcplanetracker) * Fix: Open redirect via whitespace bypass in /auth/redirect (CVE-2026-54915) (Thanks @sondt99) 🛡 [VirusTotal GitHub Action](https://github.com/crazy-max/ghaction-virustotal) analysis: * [`Tautulli-macos-v2.17.2-universal.pkg`](https://www.virustotal.com/gui/file-analysis/NzM1YzY3ZDQxODAwY2Q1NDJkNTUwZDUzYmJiOTIyMTA6MTc4MTYyNTk2MA==/detection) * [`Tautulli-windows-v2.17.2-x64.exe`](https://www.virustotal.com/gui/file-analysis/MDMxNjI4NTdmMzFmYmI1ZGEzYmE4OGRiOTVkYTdiNjk6MTc4MTYyNTk1OA==/detection) ### v2.17.1 — Tautulli v2.17.1 - Date: 2026-05-05 - Version: v2.17.1 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.17.1 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.17.1 - Labels: Platforms: Desktop - **fixed** — Tautulli Remote App notifications failing to send - **added** — Added extra type and preroll to notification parameters - **added** — Added Simkl URL to notification parameters - **security** — Fixed remote code execution via newsletter custom template directory (CVE-2026-41065) - **fixed** — Export failed when logo / square art keys were included - **fixed** — Error when browsing for folder paths - **added** — Added AV1 media flag image - **added** — Added opus media flag image - **fixed** — Clean empty directories after updating using git - **fixed** — Tautulli failing to reconnect to Plex Media Server until restarted after a connection loss at startup - **security** — Fixed path traversal in cache deletion API (CVE-2026-40605) - **fixed** — Websocket not exiting and reconnecting cleanly after changing Plex servers - **security** — Sanitize JS log errors to prevent XSS (CVE-2026-43984) - **security** — Do not store image hash for external images (CVE-2026-43986) - **changed** — Update Windows and MacOS packages to Python 3.13 - **changed** — Update Snap package to core24 - **changed** — Using mounted folders for custom newsletter templates and scripts requires manually enabling allow_mounted_folders = 1 in the config file - **security** — Added anti-CSRF tokens and enforce POST methods to state change endpoints (CVE-2026-43985) - **changed** — Hash Tautulli cookie name and invalidate all existing login sessions after the update - **security** — Require X-Api-Key header for login through the /auth/signin endpoint ##### Changelog ###### v2.17.1 (2026-05-04) * Notifications: * Fix: Tautulli Remote App notifications failing to send. (#2669) * New: Added extra type and preroll to notification parameters. * New: Added Simkl URL to notification parameters. * Newsletters: * Fix: Remote code execution via newsletter custom template directory. (CVE-2026-41065) (Thanks @remindsec) * Exporter: * Fix: Export failed when logo / square art keys were included. (#2685) * UI: * Fix: Error when browsing for folder paths. (#2673) * New: Added AV1 media flag image. (#2676) (Thanks @little0831) * New: Added opus media flag image. * Other: * Fix: Clean empty directories after updating using git. (#2667) * Fix: Tautulli failing to reconnect to Plex Media Server until restarted after a connection loss at startup. (#2640) * Fix: Path treversal in cache deletion API. (CVE-2026-40605) (Thanks @JakePeralta7) * Fix: Websocket not exiting and reconnecting cleanly after changing Plex servers. * Fix: Sanitize JS log errors to prevent XSS. (CVE-2026-43984) (Thanks @larlarua) * Fix: Do not store image hash for external images. (CVE-2026-43986) (Thanks @larlarua) * New: Update Windows and MacOS packages to Python 3.13. * New: Update Snap package to core24. * New: Using mounted folders for custom newsletter templates and scripts requires manually enabling allow_mounted_folders = 1 in the config file. * New: Added anti-CSRF tokens and enforce POST methods to state change endpoints. (CVE-2026-43985) (Thanks @larlarua) * New: Hash Tautulli cookie name. All existing login sessions will be invalidated after the update. * New: Require X-Api-Key header for login through the /auth/signin endpoint. 🛡 [VirusTotal GitHub Action](https://github.com/crazy-max/ghaction-virustotal) analysis: * [`Tautulli-macos-v2.17.1-universal.pkg`](https://www.virustotal.com/gui/file-analysis/ZjRjYjIxMDU2NTRiZjM1NDNhZmRlMmU5Yzk1NTY0MWY6MTc3Nzk0NDg3Mw==/detection) * [`Tautulli-windows-v2.17.1-x64.exe`](https://www.virustotal.com/gui/file-analysis/YzRkNGNjMzRmYzJiYjJmYTE0ZWNjOWEwOTJmYmExZDg6MTc3Nzk0NDg3MQ==/detection) ### v2.17.0 — Tautulli v2.17.0 - Date: 2026-03-28 - Version: v2.17.0 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.17.0 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.17.0 - Labels: Platforms: Desktop - **security** — Prevent RCE in notification text evaluation (CVE-2026-28505) - **security** — Fix unauthenticated path traversal in /newsletter/image/images endpoint (CVE-2026-31831) - **security** — Fix SQL injection in get_home_stats API command (CVE-2026-31799) - **security** — Fix unsanitized JSONP callback parameter (CVE-2026-32275) - **security** — Add authentication to /pms_image_proxy endpoint (CVE-2026-31804) - **removed** — Support for Python 3.9 has been dropped; minimum Python version is now 3.10 - **fixed** — Media from other video libraries using modern Plex agents not showing up on newsletter - **fixed** — Logo images incorrectly exported as jpg instead of png - **fixed** — History modal not opening when clicking on graphs - **fixed** — Validate log path for Plex log files - **added** — Added ability to export square art images - **added** — Added ability to export theme music - **added** — Added rating to get_home_stats API command - **removed** — Removed get_apikey API command - **changed** — Updated Bootstrap CSS to v3.4.1 and decouple overrides - **changed** — Updated Bootstrap-select to v1.13.18 - **changed** — Updated third party donation logos ##### Changelog ###### v2.17.0 (2026-03-27) * Important Note! * Several security vulnerabilities have been identified in Tautulli versions <=2.16.1. Users are strongly encouraged to update to the latest Tautulli version 2.17.x. * Notes: * Support for Python 3.9 has been dropped. The minimum Python version is now 3.10. * Notifications: * Fix: Prevent RCE in notification text evaluation. (CVE-2026-28505) (Thanks @q1uf3ng) * Newsletters: * Fix: Media from other video libraries using the modern Plex agents not showing up on newsletter. * Fix: Unauthenticated path traversal in /newsletter/image/images endpoint. (CVE-2026-31831) (Thanks @JakePeralta7) * Exporter: * Fix: Logo images incorrectly exported as jpg instead of png. * New: Added ability to export square art images. * New: Added ability to export theme music. (#2654) * Graphs: * Fix: History modal not opening when clicking on graphs. (#2652) * API: * Fix: SQL injection in get_home_stats API command. (CVE-2026-31799) (Thanks @mandreko) * Fix: Unsanitized JSONP callback parameter. (CVE-2026-32275) (Thanks @mandreko) * New: Added rating to get_home_stats API command. (#2655) (Thanks @jma1ice) * Removed: get_apikey API command. * Other: * Fix: Validate log path for Plex log files. (#2632) * Fix: Add authentication to /pms_image_proxy endpoint. (CVE-2026-31804) (Thanks @mandreko) * New: Updated third party donation logos. (#2646) (Thanks @aisgbnok) * New: Update Bootstrap CSS to v3.4.1 and decouple overrides (#2662) (Thanks @aisgbnok) * New: Update Bootstrap-select to v1.13.18 (#2666) (Thanks @aisgbnok) 🛡 [VirusTotal GitHub Action](https://github.com/crazy-max/ghaction-virustotal) analysis: * [`Tautulli-macos-v2.17.0-universal.pkg`](https://www.virustotal.com/gui/file-analysis/NDQ1MTkyOGFhY2MzYzQ3Y2Q3ZTFhMzMzYTYyNGM2ZTc6MTc3NDY2MTA2Mg==/detection) * [`Tautulli-windows-v2.17.0-x64.exe`](https://www.virustotal.com/gui/file-analysis/YjRjMDAzMTI4ZWZkNDE5NzRjMGJhZTkwZjk2MDhjYmI6MTc3NDY2MTA2MA==/detection) ### v2.16.1 — Tautulli v2.16.1 - Date: 2026-02-15 - Version: v2.16.1 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.16.1 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.16.1 - Labels: Platforms: Desktop - **added** — Add Tautulli Plex token expired notification trigger - **added** — Add Ace editor for syntax highlighting and code formatting for newsletter message text - **changed** — Restrict graphs to guest user - **added** — Add DD:HH:MM time format for home stats - **added** — Add HH:MM:SS time format for activity cards - **removed** — Remove timezone from IP address modal - **changed** — Zip backup files to reduce file size ##### Changelog ###### v2.16.1 (2026-12-15) * Notifications: * New: Add Tautulli Plex token expired notification trigger. * Newsletters: * New: Add Ace editor for syntax highlighting and code formatting for newsletter message text (#2585) (Thanks @mcclown) * Graphs: * Change: Restrict graphs to guest user. * UI: * New: Add DD:HH:MM time format for home stats. * New: Add HH:MM:SS time format for activity cards. * Removed: Timezone from IP address modal. * Other: * Change: Zip backup files to reduce file size. 🛡 [VirusTotal GitHub Action](https://github.com/crazy-max/ghaction-virustotal) analysis: * [`Tautulli-macos-v2.16.1-universal.pkg`](https://www.virustotal.com/gui/file-analysis/NmFiNjFlZTk0OTllMzMxYzA0ZmU0ZGQyYWJlZWIwZDQ6MTc3MTE4ODAzNQ==/detection) * [`Tautulli-windows-v2.16.1-x64.exe`](https://www.virustotal.com/gui/file-analysis/YmFlYzBlNmU3YzUzYTdiYjgzMDYyMGIyYjMwYmNjYjE6MTc3MTE4ODAzNA==/detection) ### v2.16.0 — Tautulli v2.16.0 - Date: 2025-09-09 - Version: v2.16.0 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.16.0 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.16.0 - Labels: Platforms: Desktop - **security** — Validate image path in /image endpoints (CVE-2025-58760) - **security** — Validate image path in /pms_image_proxy endpoints (CVE-2025-58761) - **security** — Validate image format in /pms_image_proxy endpoint (CVE-2025-58762) - **security** — Don't run git command with shell (CVE-2025-58763) - **fixed** — Race condition in image cache directory creation - **fixed** — Update poster click-through overlay to new Plex logo ##### Changelog ###### v2.16.0 (2025-09-08) * Important Note! * Several security vulnerabilities have been identified in Tautulli versions <=2.15.3. Users are strongly encouraged to update to the latest Tautulli version 2.16.x. * UI: * Fix: Update poster click-through overlay to new Plex logo. (#2584) (Thanks @TheMeanCanEHdian) * Other: * Fix: Race condition in image cache directory creation. (#2580) (Thanks @keithah) * Fix: Validate image path in /image endpoints. (CVE-2025-58760) (Thanks @d-xuan) * Fix: Validate image path in /pms_image_proxy endpoints. (CVE-2025-58761) (Thanks @d-xuan) * Fix: Validate image format in /pms_image_proxy endpoint. (CVE-2025-58762) (Thanks @d-xuan) * Fix: Don't run git command with shell. (CVE-2025-58763) (Thanks @d-xuan) 🛡 [VirusTotal GitHub Action](https://github.com/crazy-max/ghaction-virustotal) analysis: * [`Tautulli-macos-v2.16.0-universal.pkg`](https://www.virustotal.com/gui/file-analysis/MjEwYmYxZWU3NzEwYjgyYzZiMDMyMWJiNzAzNTliNzM6MTc1NzM3OTk0OA==/detection) * [`Tautulli-windows-v2.16.0-x64.exe`](https://www.virustotal.com/gui/file-analysis/NWY3ZWY2NDVlM2FjZTYxOGFjM2QwZjhmYzQzYjNiNTM6MTc1NzM3OTk0Ng==/detection) ### v2.15.3 — Tautulli v2.15.3 - Date: 2025-08-03 - Version: v2.15.3 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.15.3 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.15.3 - Labels: Platforms: Desktop - **added** — Added hearingImpaired for subtitles and visualImpaired for audio attributes to exporter fields - **fixed** — Remove duplicate "Total" entry in graph tooltips - **fixed** — Failing to retrieve collections / playlists with over 1000 items - **fixed** — Scrollbar not showing on macosx and webkit browsers - **fixed** — Incorrect rounding of minutes in global stats play duration - **fixed** — Disable browser autocomplete for notification agent and newsletter agent configurations - **added** — Added ability to return svg files using pms_image_proxy API command - **added** — Added ability to set config values using environment variables ##### Changelog ###### v2.15.3 (2025-08-03) * Exporter: * New: Added hearingImpaired for subtitles and visualImpaired for audio attributes to exporter fields. * Graphs: * Fix: Remove duplicate "Total" entry in graph tooltips. (Thanks @zdimension) (#2534) * UI: * Fix: Failing to retrieve collections / playlists with over 1000 items. * Fix: Scrollbar not showing on macosx and webkit browsers. (#2221) * Fix: Incorrect rounding of minutes in global stats play duration. * Fix: Disable browser autocomplete for notification agent and newsletter agent configurations. (#2557) * API: * New: Added ability to return svg files using pms_image_proxy API command. * Other: * New: Added ability to set config values using environment variables. (Thanks @komuw) (#2309, #2543) 🛡 [VirusTotal GitHub Action](https://github.com/crazy-max/ghaction-virustotal) analysis: * [`Tautulli-macos-v2.15.3-universal.pkg`](https://www.virustotal.com/gui/file-analysis/MmZhOTUwMjU5OThkY2IwYTM2ZDlmN2U4OWIxNzQ0NTE6MTc1NDI0MjAzNg==/detection) * [`Tautulli-windows-v2.15.3-x64.exe`](https://www.virustotal.com/gui/file-analysis/NjM4YzhmMDg2YzgwM2RiMGM3YTIyOGExODZlN2E4OWI6MTc1NDI0MjAzNA==/detection) ### v2.15.2 — Tautulli v2.15.2 - Date: 2025-04-12 - Version: v2.15.2 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.15.2 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.15.2 - Labels: Platforms: Desktop - **added** — Added link to library by clicking media type icon in Activity - **added** — Added stream count to tab title on homepage - **fixed** — Check stream watched status before stream stopped status in History - **fixed** — ntfy notifications failing to send if provider link is blank - **fixed** — Check Pushover notification attachment is under 5MB limit - **fixed** — Track URLs redirecting to the correct media page in Notifications - **added** — Added audio profile notification parameters - **added** — Added PATCH method for Webhook notifications - **added** — Added Total line to daily streams graph - **fixed** — Do not redirect API requests to the login page - **changed** — Swap source and stream columns in stream info modal - **fixed** — Various typos - **fixed** — CherryPy CORS response header not being set correctly ##### Changelog ###### v2.15.2 (2025-04-12) * Activity: * New: Added link to library by clicking media type icon. * New: Added stream count to tab title on homepage. (#2517) * History: * Fix: Check stream watched status before stream stopped status. (#2506) * Notifications: * Fix: ntfy notifications failing to send if provider link is blank. * Fix: Check Pushover notification attachment is under 5MB limit. (#2396) * Fix: Track URLs redirecting to the correct media page. (#2513) * New: Added audio profile notification parameters. * New: Added PATCH method for Webhook notifications. * Graphs: * New: Added Total line to daily streams graph. (Thanks @zdimension) (#2497) * UI: * Fix: Do not redirect API requests to the login page. (#2490) * Change: Swap source and stream columns in stream info modal. * Other: * Fix: Various typos. (Thanks @luzpaz) (#2520) * Fix: CherryPy CORS response header not being set correctly. (#2279) 🛡 [VirusTotal GitHub Action](https://github.com/crazy-max/ghaction-virustotal) analysis: * [`Tautulli-macos-v2.15.2-universal.pkg`](https://www.virustotal.com/gui/file-analysis/YzU0MmY4MGM2NzkzODhkYTc2NTlkZGIzYWE5NmU4M2I6MTc0NDUwMDQ3MA==/detection) * [`Tautulli-windows-v2.15.2-x64.exe`](https://www.virustotal.com/gui/file-analysis/NDAyY2UxYzJiNmZkNzFmOTA3NzQ5MGIwN2I1YzEwNTE6MTc0NDUwMDQ2Nw==/detection) ### v2.15.1 — Tautulli v2.15.1 - Date: 2025-01-11 - Version: v2.15.1 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.15.1 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.15.1 - Labels: Platforms: Desktop - **fixed** — Detection of HDR transcodes - **fixed** — Disable basic authentication for /newsletter and /image endpoints - **added** — Added logos to season and episode exports - **fixed** — Docker container https health check ###### Windows installer removed due to antivirus flagging it as a false positive (#2454). Install [v2.14.6](https://github.com/Tautulli/Tautulli/releases/tag/v2.14.6). --- ##### Changelog ###### v2.15.1 (2025-01-11) * Activity: * Fix: Detection of HDR transcodes. (Thanks @cdecker08) (#2412, #2466) * Newsletters: * Fix: Disable basic authentication for /newsletter and /image endpoints. (#2472) * Exporter: * New: Added logos to season and episode exports. * Other: * Fix Docker container https health check. 🛡 [VirusTotal GitHub Action](https://github.com/crazy-max/ghaction-virustotal) analysis: * [`Tautulli-macos-v2.15.1-universal.pkg`](https://www.virustotal.com/gui/file-analysis/YmUwZDUyMGQ0MzdjZDc3Njg5OWM3OWQ2NWQ5YWM0NmE6MTczNjYzODcxMA==/detection) * [`Tautulli-windows-v2.15.1-x64.exe`](https://www.virustotal.com/gui/file-analysis/MWYyZjIwNzhmODEwNTA3ZDI2OGIzNzFkMWYxNTNmOTQ6MTczNjYzODcwOA==/detection) ### v2.15.0 — Tautulli v2.15.0 - Date: 2024-11-24 - Version: v2.15.0 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.15.0 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.15.0 - Labels: Platforms: Desktop - **removed** — Support for Python 3.8 has been dropped; the minimum Python version is now 3.9 - **added** — Allow Telegram blockquote and tg-emoji HTML tags in notifications - **added** — Added Plex slug and Plex Watch URL notification parameters - **changed** — Update OneSignal API calls to use the new API endpoint for Tautulli Remote App notifications - **fixed** — Dumping custom dates in raw newsletter json - **fixed** — Unable to fix match for artists - **added** — Added movie and episode hasVoiceActivity attribute to exporter fields - **added** — Added subtitle canAutoSync attribute to exporter fields - **added** — Added logos to the exporter fields - **added** — Add friendly name to the top bar of config modals - **added** — Added plex slugs to metadata in the get_metadata API command - **fixed** — Tautulli failing to start with Python 3.13 ###### Windows installer removed due to antivirus flagging it as a false positive (#2454). Install [v2.14.6](https://github.com/Tautulli/Tautulli/releases/tag/v2.14.6). --- ##### Changelog ###### v2.15.0 (2024-11-24) * Notes: * Support for Python 3.8 has been dropped. The minimum Python version is now 3.9. * Notifications: * New: Allow Telegram blockquote and tg-emoji HTML tags. (Thanks @MythodeaLoL) (#2427) * New: Added Plex slug and Plex Watch URL notification parameters. (#2420) * Change: Update OneSignal API calls to use the new API endpoint for Tautulli Remote App notifications. * Newsletters: * Fix: Dumping custom dates in raw newsletter json. * History: * Fix: Unable to fix match for artists. (#2429) * Exporter: * New: Added movie and episode hasVoiceActivity attribute to exporter fields. * New: Added subtitle canAutoSync attribute to exporter fields. * New: Added logos to the exporter fields. * UI: * New: Add friendly name to the top bar of config modals. (Thanks @peagravel) (#2432) * API: * New: Added plex slugs to metadata in the get_metadata API command. * Other: * Fix: Tautulli failing to start with Python 3.13. (#2426) ### v2.14.6 — Tautulli v2.14.6 - Date: 2024-10-13 - Version: v2.14.6 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.14.6 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.14.6 - Labels: Platforms: Desktop - **fixed** — Allow formatting newsletter date parameters - **changed** — Support apscheduler compatible cron expressions in newsletters - **fixed** — Round runtime before converting to human duration in UI - **fixed** — Make recently added/watched rows touch scrollable in UI - **fixed** — Auto-updater not running ##### Changelog ###### v2.14.6 (2024-10-12) * Newsletters: * Fix: Allow formatting newsletter date parameters. * Change: Support apscheduler compatible cron expressions. * UI: * Fix: Round runtime before converting to human duration. * Fix: Make recently added/watched rows touch scrollable. * Other: * Fix: Auto-updater not running.