WRITEUP

WRITEUP
Exploit for CVE-2025-58760 - Tautulli <2.15.3 - Path Traversal
AI Analysis

This patch addresses a path traversal vulnerability in Tautulli by adding validation to ensure image paths are subdirectories of the resource directory. The fix introduces a new helper function `is_subdir` and applies it in two image-serving functions to prevent directory traversal attacks.

Attack Type
other
Complexity
moderate
Reliability
reliable
MITRE ATT&CK
T1006 - Direct Volume Access
Loading exploit code...
Download ZIP Password: eip
Authors
JonnyWong16
Vulnerability
CVE-2025-58760
Tautulli <2.15.3 - Path Traversal
HIGH
CVSS 8.6