CVE-2026-28208
EUVD-2026-890926.02.2026, 23:16
Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content anywhere on the filesystem when a crafted RAR archive is extracted on Linux/Unix. This can often lead to remote code execution (e.g., overwriting shell profiles, source code, cron jobs, etc). Version 7.5.8 has a fix for the issue.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| junrar_project | junrar | 𝑥 < 7.5.8 |
𝑥
= Vulnerable software versions