{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/vlc-media-player--3.0.24/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:videolan:vlc_media_player:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-102875"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["VLC media player (\u003c 3.0.24)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","code-execution","path-traversal"],"_cs_type":"advisory","_cs_vendors":["VideoLAN"],"content_html":"\u003cp\u003eVLC media player versions before 3.0.24 are susceptible to a path traversal vulnerability located within the skins2 ThemeLoader module. The vulnerability arises from improper validation of member names within .vlt skin archive files. An attacker can create a specially crafted .vlt archive containing path traversal sequences, such as dot-dot-slash (../) patterns, to escape the intended directory during the extraction process. By successfully exploiting this, a threat actor can write files to arbitrary locations on the host filesystem with the permissions of the user running the application. This mechanism can be leveraged to achieve remote code execution by overwriting or placing malicious Lua scripts in paths where the application or the user session executes code.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary file write operations, which can lead to remote code execution on the affected host. This affects all users running VLC media player versions prior to 3.0.24 on Windows, Linux, or macOS. If compromised, the integrity of the local user environment is at risk, potentially leading to full system compromise depending on the user's privilege level.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate all installations of VLC media player to version 3.0.24 or later immediately. Users should exercise caution when importing or applying third-party skin files from untrusted sources.\u003c/p\u003e\n","date_modified":"2026-09-29T20:29:49Z","date_published":"2026-09-29T20:29:49Z","id":"https://feed.craftedsignal.io/briefs/2026-09-vlc-path-traversal/","summary":"VLC media player versions prior to 3.0.24 contain a path traversal vulnerability in the skins2 component, allowing attackers to overwrite arbitrary files and achieve code execution via malicious .vlt skin archives.","title":"Path Traversal Vulnerability in VLC media player skins2 ThemeLoader","url":"https://feed.craftedsignal.io/briefs/2026-09-vlc-path-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - VLC Media Player (\u003c 3.0.24)","version":"https://jsonfeed.org/version/1.1"}