{"id":"CVE-2026-41245","aliases":["GHSA-hf5p-q87m-crj7"],"url":"https://o3.security/vulnerability/CVE-2026-41245","summary":"Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix","details":"### Summary\n\nA path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted.\n\n### Example\n\nGiven an extraction directory set to `/tmp/extract`, a crafted archive with an entry with the filename as `../extract_evil/file.txt` would be actually extracted to `/tmp/extract_evil/file.txt`.\n\n### Details\n\nThe `createDirectory()` and `createFile()` methods in`LocalFolderExtractor` validate extraction paths using a string prefix.","published":"2026-04-20T15:15:24.540Z","modified":"2026-08-20T10:17:13.335620Z","cvss":{"score":5.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.00336,"percentile":0.26366,"asOf":"2026-08-12"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"com.github.junrar:junrar","fixedVersion":"7.5.10"}],"fix":{"url":"https://github.com/junrar/junrar/commit/d77e9a83eb721cd51f9c23d7869d0e6ad7f952d7","label":"junrar/junrar@d77e9a8"},"references":[{"type":"WEB","url":"https://github.com/junrar/junrar/releases/tag/v7.5.10"},{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41245.json"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-41245"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41245.json"},{"type":"ADVISORY","url":"https://github.com/junrar/junrar/security/advisories/GHSA-hf5p-q87m-crj7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41245"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2459769"},{"type":"FIX","url":"https://github.com/junrar/junrar/commit/d77e9a83eb721cd51f9c23d7869d0e6ad7f952d7"},{"type":"PACKAGE","url":"https://github.com/junrar/junrar"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T10:17:13.335620Z"}}