Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix
Published Apr 20, 2026
9.3
CRITICALCVSS 3.1
EPSS 0.53%
Description
Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted. Version 7.5.10 fixes the issue.
Affected products
-
- Version < 7.5.10StatusaffectedConstraints-
- Version
- < 7.5.10
No data.
Red Hat Fuse 7
junrar
Will not fix
Red Hat JBoss Enterprise Application Platform 8
junrar
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
junrar
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Fuse 7 | junrar | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | junrar | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | junrar | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this vulnerability, avoid processing RAR archives from untrusted sources. Restrict the extraction of RAR archives to only those originating from known and verified origins. This operational control reduces the risk of exploiting the path traversal flaw in Junrar by preventing the processing of malicious archives.
References (9)
- https://access.redhat.com/security/cve/CVE-2026-41245 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2459769 Issue Tracking
- https://github.com/advisories/GHSA-hf5p-q87m-crj7 Advisory
- https://github.com/junrar/junrar/commit/d77e9a83eb721cd51f9c23d7869d0e6ad7f952d7 x_refsource_MISCPatch
- https://github.com/junrar/junrar/releases/tag/v7.5.10 x_refsource_MISCRelease Notes
- https://github.com/junrar/junrar/security/advisories/GHSA-hf5p-q87m-crj7 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41245
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41245.json
- https://www.cve.org/CVERecord?id=CVE-2026-41245
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-41245 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2459769 | Issue Tracking | |
| https://github.com/advisories/GHSA-hf5p-q87m-crj7 | Advisory | |
| https://github.com/junrar/junrar/commit/d77e9a83eb721cd51f9c23d7869d0e6ad7f952d7 | x_refsource_MISCPatch | |
| https://github.com/junrar/junrar/releases/tag/v7.5.10 | x_refsource_MISCRelease Notes | |
| https://github.com/junrar/junrar/security/advisories/GHSA-hf5p-q87m-crj7 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41245 | ||
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41245.json | ||
| https://www.cve.org/CVERecord?id=CVE-2026-41245 |
Change history (0)
No recorded changes yet.