# Tautulli v2.17.1 — Tautulli v2.17.1 - Product: Tautulli (https://whatsnew.fyi/product/tautulli) - Vendor: Tautulli - Date: 2026-05-05 - Version: v2.17.1 - Original notes: https://github.com/Tautulli/Tautulli/releases/tag/v2.17.1 - Permalink: https://whatsnew.fyi/product/tautulli/releases/v2.17.1 - Labels: Platforms: Desktop What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. --- - **fixed** — Tautulli Remote App notifications failing to send - **added** — Added extra type and preroll to notification parameters - **added** — Added Simkl URL to notification parameters - **security** — Fixed remote code execution via newsletter custom template directory (CVE-2026-41065) - **fixed** — Export failed when logo / square art keys were included - **fixed** — Error when browsing for folder paths - **added** — Added AV1 media flag image - **added** — Added opus media flag image - **fixed** — Clean empty directories after updating using git - **fixed** — Tautulli failing to reconnect to Plex Media Server until restarted after a connection loss at startup - **security** — Fixed path traversal in cache deletion API (CVE-2026-40605) - **fixed** — Websocket not exiting and reconnecting cleanly after changing Plex servers - **security** — Sanitize JS log errors to prevent XSS (CVE-2026-43984) - **security** — Do not store image hash for external images (CVE-2026-43986) - **changed** — Update Windows and MacOS packages to Python 3.13 - **changed** — Update Snap package to core24 - **changed** — Using mounted folders for custom newsletter templates and scripts requires manually enabling allow_mounted_folders = 1 in the config file - **security** — Added anti-CSRF tokens and enforce POST methods to state change endpoints (CVE-2026-43985) - **changed** — Hash Tautulli cookie name and invalidate all existing login sessions after the update - **security** — Require X-Api-Key header for login through the /auth/signin endpoint ##### Changelog ###### v2.17.1 (2026-05-04) * Notifications: * Fix: Tautulli Remote App notifications failing to send. (#2669) * New: Added extra type and preroll to notification parameters. * New: Added Simkl URL to notification parameters. * Newsletters: * Fix: Remote code execution via newsletter custom template directory. (CVE-2026-41065) (Thanks @remindsec) * Exporter: * Fix: Export failed when logo / square art keys were included. (#2685) * UI: * Fix: Error when browsing for folder paths. (#2673) * New: Added AV1 media flag image. (#2676) (Thanks @little0831) * New: Added opus media flag image. * Other: * Fix: Clean empty directories after updating using git. (#2667) * Fix: Tautulli failing to reconnect to Plex Media Server until restarted after a connection loss at startup. (#2640) * Fix: Path treversal in cache deletion API. (CVE-2026-40605) (Thanks @JakePeralta7) * Fix: Websocket not exiting and reconnecting cleanly after changing Plex servers. * Fix: Sanitize JS log errors to prevent XSS. (CVE-2026-43984) (Thanks @larlarua) * Fix: Do not store image hash for external images. (CVE-2026-43986) (Thanks @larlarua) * New: Update Windows and MacOS packages to Python 3.13. * New: Update Snap package to core24. * New: Using mounted folders for custom newsletter templates and scripts requires manually enabling allow_mounted_folders = 1 in the config file. * New: Added anti-CSRF tokens and enforce POST methods to state change endpoints. (CVE-2026-43985) (Thanks @larlarua) * New: Hash Tautulli cookie name. All existing login sessions will be invalidated after the update. * New: Require X-Api-Key header for login through the /auth/signin endpoint. 🛡 [VirusTotal GitHub Action](https://github.com/crazy-max/ghaction-virustotal) analysis: * [`Tautulli-macos-v2.17.1-universal.pkg`](https://www.virustotal.com/gui/file-analysis/ZjRjYjIxMDU2NTRiZjM1NDNhZmRlMmU5Yzk1NTY0MWY6MTc3Nzk0NDg3Mw==/detection) * [`Tautulli-windows-v2.17.1-x64.exe`](https://www.virustotal.com/gui/file-analysis/YzRkNGNjMzRmYzJiYjJmYTE0ZWNjOWEwOTJmYmExZDg6MTc3Nzk0NDg3MQ==/detection)