

This is why when people say that FOSS is more secure than closed source I always laugh. Those people seem to think that because it’s open source that not only has it been reviewed in depth by security experts who know every single possible vulnerability, but that they found every vulnerability, fixed them, put in PRs that were then approved by the creator, who then made a new release with those fixes……. every time a new potential vulnerability is discovered in the libraries etc that it’s using.
Often it just leads to situations like this - known big vulnerabilities that are just never fixed.
While I don’t think it’s a great look, employees can be customers/users too. I can’t imagine a Plex employee wouldn’t actually use Plex either. They should have disclosed that they’re an employee in the review.