[Android] Prevent path traversal in Remote Access playback endpoints

Nicolas Pomepuy git at videolan.org
Fri Oct 2 07:29:56 UTC 2026


vlc-android | branch: master | Nicolas Pomepuy <nicolas at videolabs.io> | Thu Sep 24 14:00:30 2026 +0200| [96f7d4d793e09227e2d780bb651321c26325574c] | committer: Nicolas Pomepuy

Prevent path traversal in Remote Access playback endpoints

> https://code.videolan.org/videolan/vlc-android/commit/96f7d4d793e09227e2d780bb651321c26325574c
---

 .../routing/RemoteAccessRoutingPlayback.kt                   | 12 ++++++++++++
 1 file changed, 12 insertions(+)

diff --git a/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingPlayback.kt b/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingPlayback.kt
index 64b2be6d5e..cc9307bf3a 100644
--- a/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingPlayback.kt
+++ b/application/remote-access-server/src/main/java/org/videolan/vlc/remoteaccessserver/routing/RemoteAccessRoutingPlayback.kt
@@ -76,6 +76,12 @@ fun Route.playbackRouting(appContext: Context, scope: CoroutineScope, settings:
         val append = call.request.queryParameters["append"] == "true"
         val asAudio = call.request.queryParameters["audio"] == "true"
         val path = call.request.queryParameters["path"]
+        
+        if (!isPathSafeForRemoteAccess(path)) {
+            call.respond(HttpStatusCode.Forbidden)
+            return at get
+        }
+
         call.request.queryParameters["id"]?.let { id ->
 
             val medias = appContext.getFromMl {
@@ -180,6 +186,12 @@ fun Route.playbackRouting(appContext: Context, scope: CoroutineScope, settings:
                     call.respond(HttpStatusCode.NotFound)
                     return at get
                 }
+                
+                if (!isPathSafeForRemoteAccess(path)) {
+                    call.respond(HttpStatusCode.Forbidden)
+                    return at get
+                }
+
                 val decodedPath = Uri.decode(path)
 
                 val dataset = LiveDataset<MediaLibraryItem>()



More information about the Android mailing list