[Android] Prevent arbitrary directory traversal in browse list endpoint
Nicolas Pomepuy
git at videolan.org
Fri Oct 2 07:29:56 UTC 2026
vlc-android | branch: master | Nicolas Pomepuy <nicolas at videolabs.io> | Thu Sep 24 13:28:00 2026 +0200| [a2bcb860724248ba79691749df112fb2cfb776a4] | committer: Nicolas Pomepuy
Prevent arbitrary directory traversal in browse list endpoint
> https://code.videolan.org/videolan/vlc-android/commit/a2bcb860724248ba79691749df112fb2cfb776a4
---
.../vlc/remoteaccessserver/routing/RemoteAccessRoutingFile.kt | 6 ++++++
1 file changed, 6 insertions(+)
diff --git a/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingFile.kt b/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingFile.kt
index 4582c09cd1..5f84a057e7 100644
--- a/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingFile.kt
+++ b/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingFile.kt
@@ -388,6 +388,12 @@ fun Route.authenticatedFileRouting(appContext: Context, scope: CoroutineScope, s
call.respond(HttpStatusCode.NotFound)
return at get
}
+
+ if (!isPathSafeForRemoteAccess(path)) {
+ call.respond(HttpStatusCode.Forbidden)
+ return at get
+ }
+
val decodedPath = Uri.decode(path)
val dataset = LiveDataset<MediaLibraryItem>()
More information about the Android
mailing list