CVE-2026-102875

high

Description

VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection.

References

https://www.vulncheck.com/advisories/vlc-media-player-before-3.0.24-path-traversal-via-skins2

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-89410

https://code.videolan.org/videolan/vlc/-/commit/8d43e99c2c01d9aab3ecad00e7a102806262b06b

https://code.videolan.org/videolan/vlc/-/commit/59934edbd03c6c1147d75d6c91e96633b710ec31

https://code.videolan.org/videolan/vlc/-/blob/3.0.23/modules/gui/skins2/src/theme_loader.cpp

https://code.videolan.org/videolan/vlc

Details

Source: Mitre, NVD

Published: 2026-09-29

Updated: 2026-09-30

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Severity: High

CVSS v4

Base Score: 8.5

Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00167