CVE-2026-41245
EUVD-2026-2387220.04.2026, 16:16
Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted. Version 7.5.10 fixes the issue.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| junrar_project | junrar | 𝑥 < 7.5.10 |
𝑥
= Vulnerable software versions