[Android] Prevent path traversal in Remote Access playback endpoints
Nicolas Pomepuy
git at videolan.org
Fri Oct 2 07:29:56 UTC 2026
vlc-android | branch: master | Nicolas Pomepuy <nicolas at videolabs.io> | Thu Sep 24 14:00:30 2026 +0200| [96f7d4d793e09227e2d780bb651321c26325574c] | committer: Nicolas Pomepuy
Prevent path traversal in Remote Access playback endpoints
> https://code.videolan.org/videolan/vlc-android/commit/96f7d4d793e09227e2d780bb651321c26325574c
---
.../routing/RemoteAccessRoutingPlayback.kt | 12 ++++++++++++
1 file changed, 12 insertions(+)
diff --git a/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingPlayback.kt b/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingPlayback.kt
index 64b2be6d5e..cc9307bf3a 100644
--- a/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingPlayback.kt
+++ b/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingPlayback.kt
@@ -76,6 +76,12 @@ fun Route.playbackRouting(appContext: Context, scope: CoroutineScope, settings:
val append = call.request.queryParameters["append"] == "true"
val asAudio = call.request.queryParameters["audio"] == "true"
val path = call.request.queryParameters["path"]
+
+ if (!isPathSafeForRemoteAccess(path)) {
+ call.respond(HttpStatusCode.Forbidden)
+ return at get
+ }
+
call.request.queryParameters["id"]?.let { id ->
val medias = appContext.getFromMl {
@@ -180,6 +186,12 @@ fun Route.playbackRouting(appContext: Context, scope: CoroutineScope, settings:
call.respond(HttpStatusCode.NotFound)
return at get
}
+
+ if (!isPathSafeForRemoteAccess(path)) {
+ call.respond(HttpStatusCode.Forbidden)
+ return at get
+ }
+
val decodedPath = Uri.decode(path)
val dataset = LiveDataset<MediaLibraryItem>()
More information about the Android
mailing list