[Android] Add defense path validation to download endpoints

Nicolas Pomepuy git at videolan.org
Fri Oct 2 07:29:56 UTC 2026


vlc-android | branch: master | Nicolas Pomepuy <nicolas at videolabs.io> | Thu Sep 24 14:33:30 2026 +0200| [1ab17d00be14cff1f6a80611a0364779ebef794f] | committer: Nicolas Pomepuy

Add defense path validation to download endpoints

> https://code.videolan.org/videolan/vlc-android/commit/1ab17d00be14cff1f6a80611a0364779ebef794f
---

 .../remoteaccessserver/routing/RemoteAccessRoutingResources.kt    | 8 ++++++++
 1 file changed, 8 insertions(+)

diff --git a/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingResources.kt b/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingResources.kt
index 7d9129029d..63ac5cf168 100644
--- a/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingResources.kt
+++ b/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingResources.kt
@@ -105,6 +105,10 @@ fun Route.resourceRouting(appContext: Context, settings: SharedPreferences) {
                     //simple media. It's a direct download
                     appContext.getFromMl { getMedia(id.toLong()) }?.let { media ->
                         media.uri.path?.let { path ->
+                            if (!isPathSafeForRemoteAccess(path)) {
+                                call.respond(HttpStatusCode.Forbidden)
+                                return at get
+                            }
                             val file = File(path)
                             val name = media.title.slugify("_") + media.uri.toString().substring(media.uri.toString().lastIndexOf("."))
                             call.response.header(
@@ -143,6 +147,10 @@ fun Route.resourceRouting(appContext: Context, settings: SharedPreferences) {
             call.respond(HttpStatusCode.NotFound)
             return at get
         }
+        if (!isPathSafeForRemoteAccess(path)) {
+            call.respond(HttpStatusCode.Forbidden)
+            return at get
+        }
         val file = File(path)
         if (!file.exists() || !file.canRead()) {
             call.respond(HttpStatusCode.NotFound)



More information about the Android mailing list