Path traversal in junrar - CVE-2026-28208
Published: April 27, 2026
junrar
Detailed vulnerability description
The vulnerability allows a remote attacker to write arbitrary files with attacker-controlled content.
The vulnerability exists due to path traversal in LocalFolderExtractor when extracting a crafted RAR archive on Linux/Unix. A remote attacker can supply a specially crafted archive entry with backslash-separated traversal sequences to write arbitrary files with attacker-controlled content.
Windows is not affected because backslashes are treated as path separators there, causing canonical path resolution to block the traversal.