Path traversal in junrar - CVE-2026-41245
Published: April 27, 2026
junrar
Detailed vulnerability description
The vulnerability allows a remote attacker to write arbitrary files with attacker-controlled content into sibling directories.
The vulnerability exists due to path traversal in LocalFolderExtractor when extracting a crafted RAR archive. A remote attacker can supply a specially crafted archive entry path to write arbitrary files with attacker-controlled content into sibling directories.
The issue stems from createDirectory() and createFile() validating extraction paths using a string prefix.