CyberRota Analysis
AI-GeneratedPlex Media Server versions prior to 1.43.3.10861 are vulnerable to a path traversal attack due to insufficient validation of the url parameter, allowing an attacker with a valid session token to access any file the target user can read, including sensitive tokens that control the Plex account. This vulnerability poses a risk primarily to users who have exposed their Plex servers to untrusted networks, as a LAN-adjacent attacker could exploit it using a manipulated X-Forwarded-For header. Organizations and individuals using affected versions should prioritize upgrading to mitigate potential unauthorized access to sensitive information.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken, which grants control of the Plex account and server. A LAN-adjacent attacker with a client-supplied X-Forwarded-For header could exploit the same issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)