Researchers publish PoCs for patched Plex Media Server flaws, including n-day RCEs
evilsocket · x · 2026-09-11
Researcher Zenofex reverse engineered Plex Media Server patches between builds 1.43.3.10828 and 1.43.4.10903 and published reproducible PoCs for each fixed issue, including several n-day RCEs.
- Findings span symlink arbitrary read, SSRF, RPC injection, path traversal RCE, and arbitrary file read, each with a technical writeup, version evidence, CLI usage, and expected results
- All PoCs use only Python's standard library
- No CVEs have been assigned yet
Self-hosters should upgrade to the latest release immediately.
More from Safety
- Cambridge's David Krueger launches movement on existential AI risk, opens sign-ups — DavidSKrueger · 2026-09-11
- Cambridge AI safety researcher David Krueger warns 'AI could kill us all' — DavidSKrueger · 2026-09-11
- Romney Calls AI Safeguards Top National Priority as Anthropic Urges Global Development Pause — michael_nielsen · 2026-09-11
- AI safety testing is broken on all three fronts: labs, paid auditors and nonprofits all face warped incentives — joshua_saxe · 2026-09-11
- US lawmakers call for new AI rules after Anthropic researcher's safety warnings — XIFAQ · 2026-09-11
- The First Dangerous AI Won't Have Bad Intentions — It'll Be Great at Executing Ours — gixxerscott · 2026-09-11