CVE-2020-5741: Plex Media Server Remote Code Execution Vulnerability

Published May 8, 2020
·
Updated

Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

Other sources

Plex Media Server contains a remote code execution vulnerability that allows an attacker with access to the server administrator's Plex account to upload a malicious file via the Camera Upload feature and have the media server execute it.

CISA

Affected Software

5 affected components
Plex media server
Plex media server<1.19.3
Microsoft Windows
All of the following
Plex media server<1.19.3
Microsoft Windows

Event History

May 8, 2020
CVE Published
via MITRE·12:02 PM
Data Sourced
via MITRE·12:02 PM
DescriptionWeakness
Data Sourced
via NVD·01:15 PM
DescriptionSeverityWeaknessAffected Software
Mar 10, 2023
Known Exploited
via CISA·12:00 AM
Aug 15, 2025
News Published
via BleepingComputer·11:41 AM
Aug 23, 2025
News Published
via BleepingComputer·11:44 AM
Dec 11, 2025
News Published
via The Register·04:45 PM
News Published
via The Register·04:49 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2020-5741?

CVE-2020-5741 is a remote code execution vulnerability in Plex Media Server.

2

How does CVE-2020-5741 work?

CVE-2020-5741 allows an attacker with administrative access to the Plex server to upload a malicious file through the Camera Upload feature, which can then be executed by the media server.

3

What is the affected software?

The affected software is Plex Media Server.

4

Can this vulnerability be exploited remotely?

No, this vulnerability can only be exploited by an attacker with access to the server administrator's Plex account.

5

How can I protect myself from CVE-2020-5741?

To protect yourself, ensure that your Plex server is always running the latest version and regularly update it when new releases or security patches are available.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203