Plex Media Server - Security Update

We recently received a report via our bug bounty program that there was a potential security issue affecting PMS versions 1.41.7.x to 1.42.0.x. Thanks to that user, we were able to address the issue and continue to improve our security and defenses.

We strongly recommend that everyone have their PMS updated to the most recent version as soon as possible, if you have not already done so.

The new version, 1.42.1, is now available to update through the PMS management page or you can download it here: https://www.plex.tv/media-server-downloads/

25 Likes

As a follow-up to the original report and in an abundance of caution due to a population of servers still on an affected Plex Media Server version (versions 1.41.7.x to 1.42.0.x), we have made adjustments for access to affected servers. Specifically, other users to which the server owner has granted access to the server will not be able to connect to it while the server is running an affected version. Once the server is updated to a fixed version, other users will be able to access again. Server owners will still be able to access the server as normal.

Again, we strongly recommend that everyone have their Plex Media Server updated to the most recent version as soon as possible, if you have not already done so.

The new version, 1.42.1, is now available to update through the PMS management page or you can download it here: https://www.plex.tv/media-server-downloads/

7 Likes