# Tautulli v2.17.0 — Tautulli v2.17.0 - Product: Tautulli (https://whatsnew.fyi/product/tautulli) - Vendor: Tautulli - Date: 2026-03-28 - Version: v2.17.0 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.17.0 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.17.0 - Labels: Platforms: Desktop What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **security** — Prevent RCE in notification text evaluation (CVE-2026-28505) - **security** — Fix unauthenticated path traversal in /newsletter/image/images endpoint (CVE-2026-31831) - **security** — Fix SQL injection in get_home_stats API command (CVE-2026-31799) - **security** — Fix unsanitized JSONP callback parameter (CVE-2026-32275) - **security** — Add authentication to /pms_image_proxy endpoint (CVE-2026-31804) - **removed** — Support for Python 3.9 has been dropped; minimum Python version is now 3.10 - **fixed** — Media from other video libraries using modern Plex agents not showing up on newsletter - **fixed** — Logo images incorrectly exported as jpg instead of png - **fixed** — History modal not opening when clicking on graphs - **fixed** — Validate log path for Plex log files - **added** — Added ability to export square art images - **added** — Added ability to export theme music - **added** — Added rating to get_home_stats API command - **removed** — Removed get_apikey API command - **changed** — Updated Bootstrap CSS to v3.4.1 and decouple overrides - **changed** — Updated Bootstrap-select to v1.13.18 - **changed** — Updated third party donation logos ##### Changelog ###### v2.17.0 (2026-03-27) * Important Note! * Several security vulnerabilities have been identified in Tautulli versions <=2.16.1. Users are strongly encouraged to update to the latest Tautulli version 2.17.x. * Notes: * Support for Python 3.9 has been dropped. The minimum Python version is now 3.10. * Notifications: * Fix: Prevent RCE in notification text evaluation. (CVE-2026-28505) (Thanks @q1uf3ng) * Newsletters: * Fix: Media from other video libraries using the modern Plex agents not showing up on newsletter. * Fix: Unauthenticated path traversal in /newsletter/image/images endpoint. (CVE-2026-31831) (Thanks @JakePeralta7) * Exporter: * Fix: Logo images incorrectly exported as jpg instead of png. * New: Added ability to export square art images. * New: Added ability to export theme music. (#2654) * Graphs: * Fix: History modal not opening when clicking on graphs. (#2652) * API: * Fix: SQL injection in get_home_stats API command. (CVE-2026-31799) (Thanks @mandreko) * Fix: Unsanitized JSONP callback parameter. (CVE-2026-32275) (Thanks @mandreko) * New: Added rating to get_home_stats API command. (#2655) (Thanks @jma1ice) * Removed: get_apikey API command. * Other: * Fix: Validate log path for Plex log files. (#2632) * Fix: Add authentication to /pms_image_proxy endpoint. (CVE-2026-31804) (Thanks @mandreko) * New: Updated third party donation logos. (#2646) (Thanks @aisgbnok) * New: Update Bootstrap CSS to v3.4.1 and decouple overrides (#2662) (Thanks @aisgbnok) * New: Update Bootstrap-select to v1.13.18 (#2666) (Thanks @aisgbnok) 🛡 [VirusTotal GitHub Action](https://github.com/crazy-max/ghaction-virustotal) analysis: * [`Tautulli-macos-v2.17.0-universal.pkg`](https://www.virustotal.com/gui/file-analysis/NDQ1MTkyOGFhY2MzYzQ3Y2Q3ZTFhMzMzYTYyNGM2ZTc6MTc3NDY2MTA2Mg==/detection) * [`Tautulli-windows-v2.17.0-x64.exe`](https://www.virustotal.com/gui/file-analysis/YjRjMDAzMTI4ZWZkNDE5NzRjMGJhZTkwZjk2MDhjYmI6MTc3NDY2MTA2MA==/detection)