---
id: CVE-2026-102875
title: >-
  VLC media player before 3.0.24 contains a path traversal vulnerability in the
  skins2 ThemeLoader that fails to validate member names in .vlt skin archives
summary: >-
  VLC media player before 3.0.24 contains a path traversal vulnerability in the
  skins2 ThemeLoader that fails to validate member names in .vlt skin archives.
  Attackers can craft malicious skin files with path traversal sequences to
  write a…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-22
vendor: videolan
product: vlc
affected:
  - vlc < 3.0.24
published: '2026-09-29'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T20:17:18.053'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102875'
references:
  - url: 'https://code.videolan.org/videolan/vlc'
    label: disclosure@vulncheck.com
  - url: >-
      https://code.videolan.org/videolan/vlc/-/blob/3.0.23/modules/gui/skins2/src/theme_loader.cpp
    label: disclosure@vulncheck.com
  - url: >-
      https://code.videolan.org/videolan/vlc/-/commit/59934edbd03c6c1147d75d6c91e96633b710ec31
    label: disclosure@vulncheck.com
  - url: >-
      https://code.videolan.org/videolan/vlc/-/commit/8d43e99c2c01d9aab3ecad00e7a102806262b06b
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/vlc-media-player-before-3.0.24-path-traversal-via-skins2
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-29T20:46:06.442Z'
---

## Overview

VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua script injection.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
