# Plex Media Server Remote Code Execution Vulnerability

**URL:** <https://forums.plex.tv/t/plex-media-server-remote-code-execution-vulnerability/834297>\
**Category:** General Discussions\
**Created:** [March 13, 2023, 4:06am UTC](https://forums.plex.tv/t/plex-media-server-remote-code-execution-vulnerability/834297 "2023-03-13T04:06:15Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![FordGuy61](https://avatars.discourse-cdn.com/v4/letter/f/22d042/32.png) [@FordGuy61](https://forums.plex.tv/u/FordGuy61)\
**Post date:** [March 13, 2023, 4:25am UTC](https://forums.plex.tv/t/plex-media-server-remote-code-execution-vulnerability/834297/2 "2023-03-13T04:25:19Z")

</div>

Has something changed since 2020?

Run PMS 1.19.3 or later. Current is 1.31.1.6782.

> [@Security: Regarding CVE-2020-5741](https://forums.plex.tv/t/security-regarding-cve-2020-5741/586819):
>
> Hello, We have recently been made aware of a security vulnerability related to Plex Media Server. This issue allowed an attacker with access to the server administrator’s Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it. This could be done by setting the server data directory to overlap with the content location for a library on which Camera Upload was enabled. This issue could not be exploited without first gaining access to the server’…

---

_[View the full topic](https://forums.plex.tv/t/plex-media-server-remote-code-execution-vulnerability/834297)._
