v2.16.0Desktop
Tautulli v2.16.0
Fixed 2
- Race condition in image cache directory creation
- Update poster click-through overlay to new Plex logo
Security 4
- Validate image path in /image endpoints (CVE-2025-58760)
- Validate image path in /pms_image_proxy endpoints (CVE-2025-58761)
- Validate image format in /pms_image_proxy endpoint (CVE-2025-58762)
- Don't run git command with shell (CVE-2025-58763)
Changelog
v2.16.0 (2025-09-08)
- Important Note!
- Several security vulnerabilities have been identified in Tautulli versions <=2.15.3. Users are strongly encouraged to update to the latest Tautulli version 2.16.x.
- UI:
- Fix: Update poster click-through overlay to new Plex logo. (#2584) (Thanks @TheMeanCanEHdian)
- Other:
- Fix: Race condition in image cache directory creation. (#2580) (Thanks @keithah)
- Fix: Validate image path in /image endpoints. (CVE-2025-58760) (Thanks @d-xuan)
- Fix: Validate image path in /pms_image_proxy endpoints. (CVE-2025-58761) (Thanks @d-xuan)
- Fix: Validate image format in /pms_image_proxy endpoint. (CVE-2025-58762) (Thanks @d-xuan)
- Fix: Don't run git command with shell. (CVE-2025-58763) (Thanks @d-xuan)
🛡 VirusTotal GitHub Action analysis: