All vulnerabilities

CVE-2026-41245

Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix

Description

Summary

A path traversal vulnerability in LocalFolderExtractor allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted.

Example

Given an extraction directory set to /tmp/extract, a crafted archive with an entry with the filename as ../extract_evil/file.txt would be actually extracted to /tmp/extract_evil/file.txt.

Details

The createDirectory() and createFile() methods inLocalFolderExtractor validate extraction paths using a string prefix.

Patch Available

Fix available through Seal Security. 

No upgrade required, protect your application instantly.

Fix without upgrading
Score
5.9
Severity
Medium
Ecosystem
Java
Publish Date
April 16, 2026
Modified Date
May 5, 2026
Score Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Versions