Detects Tautulli instances before version 2.17.0 where the notification template eval sandbox can be bypassed via nested code objects (lambda expressions). The str_eval() function only checks allowlisted names at the top-level code object — attributes accessed inside lambdas are stored in co_consts and never validated. When NOTIFY_TEXT_EVAL is enabled in Advanced Settings, an admin can execute arbitrary Python commands on the server. Update to Tautulli v2.17.0 or later.
Is your app exploitable through CVE-2026-28505?
Scan your domain free