WRITEUP
WRITEUP
Exploit for CVE-2025-58760
- Tautulli <2.15.3 - Path Traversal
AI Analysis
This patch addresses a path traversal vulnerability in Tautulli by adding validation to ensure image paths are subdirectories of the resource directory. The fix introduces a new helper function `is_subdir` and applies it in two image-serving functions to prevent directory traversal attacks.
Attack Type
other
Complexity
moderate
Reliability
reliable
MITRE ATT&CK
Click anywhere or press Esc to close