Plausible v3.2.1 patches critical RCE vulnerability
Plausible Analytics drops v3.2.1 to address a remote code execution vulnerability in the Storybook endpoint affecting self-hosted versions 3.0.0+. The update also introduces strict order funnels and upgrades the backend to Elixir 1.19.
The v3.2.1 update is a critical "stop everything and patch" moment for self-hosted Plausible users due to a remote code execution vulnerability in the exposed Storybook endpoint. While the release also adds strict order funnels for path analysis and migrates the backend to Elixir 1.19 for better performance, the security fix is the primary driver for immediate manual intervention by Community Edition admins.
DISCOVERED
2h ago
2026-05-17
PUBLISHED
2h ago
2026-05-17
RELEVANCE