In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69416.json"
[ { "events": [ { "introduced": "0" }, { "last_affected": "1.43.0.10389" } ] } ]