VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection.
https://www.vulncheck.com/advisories/vlc-media-player-before-3.0.24-path-traversal-via-skins2
https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-89410
https://code.videolan.org/videolan/vlc/-/commit/8d43e99c2c01d9aab3ecad00e7a102806262b06b
https://code.videolan.org/videolan/vlc/-/commit/59934edbd03c6c1147d75d6c91e96633b710ec31
https://code.videolan.org/videolan/vlc/-/blob/3.0.23/modules/gui/skins2/src/theme_loader.cpp
Published: 2026-09-29
Updated: 2026-09-30
Base Score: 7.2
Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C
Severity: High
Base Score: 7.8
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: High
Base Score: 8.5
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Severity: High
EPSS: 0.00167