<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>VLC Media Player (&lt; 3.0.24) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/vlc-media-player--3.0.24/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 20:29:49 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/vlc-media-player--3.0.24/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Path Traversal Vulnerability in VLC media player skins2 ThemeLoader</title><link>https://feed.craftedsignal.io/briefs/2026-09-vlc-path-traversal/</link><pubDate>Tue, 29 Sep 2026 20:29:49 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-vlc-path-traversal/</guid><description>VLC media player versions prior to 3.0.24 contain a path traversal vulnerability in the skins2 component, allowing attackers to overwrite arbitrary files and achieve code execution via malicious .vlt skin archives.</description><content:encoded><![CDATA[<p>VLC media player versions before 3.0.24 are susceptible to a path traversal vulnerability located within the skins2 ThemeLoader module. The vulnerability arises from improper validation of member names within .vlt skin archive files. An attacker can create a specially crafted .vlt archive containing path traversal sequences, such as dot-dot-slash (../) patterns, to escape the intended directory during the extraction process. By successfully exploiting this, a threat actor can write files to arbitrary locations on the host filesystem with the permissions of the user running the application. This mechanism can be leveraged to achieve remote code execution by overwriting or placing malicious Lua scripts in paths where the application or the user session executes code.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary file write operations, which can lead to remote code execution on the affected host. This affects all users running VLC media player versions prior to 3.0.24 on Windows, Linux, or macOS. If compromised, the integrity of the local user environment is at risk, potentially leading to full system compromise depending on the user's privilege level.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update all installations of VLC media player to version 3.0.24 or later immediately. Users should exercise caution when importing or applying third-party skin files from untrusted sources.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>code-execution</category><category>path-traversal</category></item></channel></rss>