Back

CRITICAL

Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix

Published Apr 20, 2026

Description

Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted. Version 7.5.10 fixes the issue.

Affected products

Remediation

Red Hat mitigation

To mitigate this vulnerability, avoid processing RAR archives from untrusted sources. Restrict the extraction of RAR archives to only those originating from known and verified origins. This operational control reduces the risk of exploiting the path traversal flaw in Junrar by preventing the processing of malicious archives.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Apr 20, 2026
Updated Aug 18, 2026
Reserved Apr 18, 2026
CISA Vulnrichment
Updated Apr 20, 2026
NVD
Status Modified
Modified Aug 18, 2026
Red Hat
Severity Important
Public date Apr 20, 2026
GHSA-HF5P-Q87M-CRJ7