Path Traversal Vulnerability in VLC Media Player by VideoLAN
CVE-2026-102875

8.5HIGH

Key Information:

Vendor

Videolan

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-102875?

VLC Media Player versions prior to 3.0.24 are susceptible to a path traversal vulnerability due to inadequate validation of member names in .vlt skin archives. This flaw allows attackers to craft malicious skin files containing path traversal sequences. When these files are processed, they can write arbitrary files under VLC's user privileges. This presents a serious risk as attackers can leverage this vulnerability to execute arbitrary Lua scripts, potentially compromising system integrity.

Affected Version(s)

vlc 0 < 3.0.24

vlc 3.0.24

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fabian Wahle (Hap Security)
.