Path Traversal Vulnerability in VLC Media Player by VideoLAN
CVE-2026-102875
8.5HIGH
What is CVE-2026-102875?
VLC Media Player versions prior to 3.0.24 are susceptible to a path traversal vulnerability due to inadequate validation of member names in .vlt skin archives. This flaw allows attackers to craft malicious skin files containing path traversal sequences. When these files are processed, they can write arbitrary files under VLC's user privileges. This presents a serious risk as attackers can leverage this vulnerability to execute arbitrary Lua scripts, potentially compromising system integrity.
Affected Version(s)
vlc 0 < 3.0.24
vlc 3.0.24