rootpwn

medium · CVSS v3 4.3 · CVSS v4 5.3

CVE-2026-96652

Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can i…

Description

Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination.

Scores

Severity
medium
CVSS v2
5
CVSS v3
4.3
CVSS v4
5.3
EPSS

← All CVEs