GHSA-5p7w-r379-3c2mMediumCVSS 4.3

Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X...

Published
September 23, 2026
Last Modified
September 23, 2026

🔗 CVE IDs covered (1)

📋 Description

Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination.

🔗 References (6)