Command injection in VLC Media Player - #VU153081

 

Command injection in VLC Media Player - #VU153081

Published: October 1, 2026


Vulnerability identifier: #VU153081
CSH Severity: Medium
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary FTP commands.

The vulnerability exists due to command injection in FTP URL handling when processing crafted URLs. A remote attacker can trick the victim into opening a crafted FTP URL to execute arbitrary FTP commands.

Exploitation requires the FTP feature to be in use.


Affected software

VLC Media Player

Remediation

Install security update from vendor's website.

VLC Media Player - update to 3.0.24

External References

Related Security Bulletins