High severity7.8NVD Advisory· Published Sep 29, 2026
CVE-2026-102875
CVE-2026-102875
Description
VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <3.0.24
Patches
Vulnerability mechanics
References
5- code.videolan.org/videolan/vlcnvd
- code.videolan.org/videolan/vlc/-/blob/3.0.23/modules/gui/skins2/src/theme_loader.cppnvd
- code.videolan.org/videolan/vlc/-/commit/59934edbd03c6c1147d75d6c91e96633b710ec31nvd
- code.videolan.org/videolan/vlc/-/commit/8d43e99c2c01d9aab3ecad00e7a102806262b06bnvd
- www.vulncheck.com/advisories/vlc-media-player-before-3.0.24-path-traversal-via-skins2nvd
News mentions
0No linked articles in our index yet.