CVE-2026-102875: VLC media player before 3.0.24 Path Traversal via skins2
VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
VLC media playerto a version that resolves this vulnerability.Fixed in 3.0.24
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
The attacker must persuade a user to interact with a crafted .vlt skin archive. The exploit relies on path traversal entries in that archive and can write files with the privileges of the VLC user.
Are users affected without installing or loading a malicious skin?
The provided information identifies the vulnerable component as the skins2 ThemeLoader and describes exploitation through malicious .vlt skin files. It does not indicate that ordinary media playback alone triggers the issue.
What impact could successful exploitation have?
A malicious skin can write arbitrary files as the VLC user. The description states that this can enable code execution through Lua script injection, with high confidentiality, integrity, and availability impact.
Which versions should be remediated?
VLC media player versions before 3.0.24 are affected. Updating to 3.0.24 or later addresses the stated affected version range.