[Android] Prevent arbitrary directory traversal in browse list endpoint

Nicolas Pomepuy git at videolan.org
Fri Oct 2 07:29:56 UTC 2026


vlc-android | branch: master | Nicolas Pomepuy <nicolas at videolabs.io> | Thu Sep 24 13:28:00 2026 +0200| [a2bcb860724248ba79691749df112fb2cfb776a4] | committer: Nicolas Pomepuy

Prevent arbitrary directory traversal in browse list endpoint

> https://code.videolan.org/videolan/vlc-android/commit/a2bcb860724248ba79691749df112fb2cfb776a4
---

 .../vlc/remoteaccessserver/routing/RemoteAccessRoutingFile.kt       | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingFile.kt b/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingFile.kt
index 4582c09cd1..5f84a057e7 100644
--- a/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingFile.kt
+++ b/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingFile.kt
@@ -388,6 +388,12 @@ fun Route.authenticatedFileRouting(appContext: Context, scope: CoroutineScope, s
             call.respond(HttpStatusCode.NotFound)
             return at get
         }
+
+        if (!isPathSafeForRemoteAccess(path)) {
+            call.respond(HttpStatusCode.Forbidden)
+            return at get
+        }
+
         val decodedPath = Uri.decode(path)
 
         val dataset = LiveDataset<MediaLibraryItem>()



More information about the Android mailing list