PT-2026-33784 · Junrar · Junrar

·

CVE-2026-41245

·

Published

2026-04-16

·

Updated

2026-08-18

CVSS v3.1

9.3

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Junrar versions prior to 7.5.10
Description A path traversal flaw in the LocalFolderExtractor allows a remote attacker to write arbitrary files with attacker-controlled content into sibling directories during the extraction of a specially crafted RAR archive. This occurs because the createDirectory() and createFile() functions in LocalFolderExtractor validate extraction paths using a string prefix, which can be bypassed to create or modify files outside the intended extraction path.
Recommendations Update to version 7.5.10.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41245
GHSA-HF5P-Q87M-CRJ7

Affected Products

Junrar