PT-2026-22155 · Videolan · Vlc For Android
Stanislav Fort
·
Published
2026-02-26
·
Updated
2026-02-26
·
CVE-2026-26228
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
VideoLAN VLC for Android versions prior to 3.7.0
Description
The software contains a path traversal issue in the Remote Access Server routing for the authenticated endpoint ''/download''. The
file query parameter is combined into a filesystem path without proper validation, potentially allowing a network-based attacker to request files outside the intended directory. The impact is limited by Android’s security features, typically restricting access to app-internal and app-specific external storage.Recommendations
Update VideoLAN VLC for Android to version 3.7.0 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vlc For Android