Path Traversal Vulnerability in VLC media player skins2 ThemeLoader
VLC media player versions prior to 3.0.24 contain a path traversal vulnerability in the skins2 component, allowing attackers to overwrite arbitrary files and achieve code execution via malicious .vlt skin archives.
CVE search metadata
CVE search record: CVE-2026-102875. Severity: high. CVSS: 7.8. KEV: no. Product: VLC media player (< 3.0.24). Brief: Path Traversal Vulnerability in VLC media player skins2 ThemeLoader. Brief link: https://feed.craftedsignal.io/briefs/2026-09-vlc-path-traversal/
VLC media player versions before 3.0.24 are susceptible to a path traversal vulnerability located within the skins2 ThemeLoader module. The vulnerability arises from improper validation of member names within .vlt skin archive files. An attacker can create a specially crafted .vlt archive containing path traversal sequences, such as dot-dot-slash (../) patterns, to escape the intended directory during the extraction process. By successfully exploiting this, a threat actor can write files to arbitrary locations on the host filesystem with the permissions of the user running the application. This mechanism can be leveraged to achieve remote code execution by overwriting or placing malicious Lua scripts in paths where the application or the user session executes code.
Impact
Successful exploitation allows for arbitrary file write operations, which can lead to remote code execution on the affected host. This affects all users running VLC media player versions prior to 3.0.24 on Windows, Linux, or macOS. If compromised, the integrity of the local user environment is at risk, potentially leading to full system compromise depending on the user's privilege level.
Recommendation
Update all installations of VLC media player to version 3.0.24 or later immediately. Users should exercise caution when importing or applying third-party skin files from untrusted sources.
Mitigations
Upgrade VLC media player to version 3.0.24 or later.
CVE-2026-102875