10
/ 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Description
Plex Media Server (PMS) versions 1.41.7.x through 1.42.0.x are affected by an unspecified security vulnerability reported via Plex’s bug bounty program. While technical details have not been publicly disclosed, the issue was acknowledged by the vendor and resolved in version 1.42.1. The vulnerability may have posed a risk to system integrity, confidentiality, or availability, prompting a strong recommendation for all users to upgrade immediately.
Basic Information
ID
CVE-2025-34158
Source
VulnCheck
Published
Aug 21, 2025 at 13:43
Modified
Aug 21, 2025 at 14:03
Affected Product
Vendor
Plex, Inc.
Product
Plex Media Server
Version
1.41.7.x
Affected Versions
Plex, Inc. Plex Media Server 1.41.7.x