{"id":"CVE-2026-28208","summary":"Junrar has arbitrary file write due to backslash path traversal bypass in LocalFolderExtractor on Linux/Unix","details":"Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content anywhere on the filesystem when a crafted RAR archive is extracted on Linux/Unix. This can often lead to remote code execution (e.g., overwriting shell profiles, source code, cron jobs, etc). Version 7.5.8 has a fix for the issue.","aliases":["GHSA-j273-m5qq-6825"],"modified":"2026-08-12T15:32:09.562107Z","published":"2026-02-26T22:20:03.765Z","database_specific":{"cwe_ids":["CWE-22"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28208.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/junrar/junrar/releases/tag/v7.5.8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28208.json"},{"type":"ADVISORY","url":"https://github.com/junrar/junrar/security/advisories/GHSA-j273-m5qq-6825"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-28208"},{"type":"FIX","url":"https://github.com/junrar/junrar/commit/947ff1d33f00f940aa68ae2593500291d799d954"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/junrar/junrar","events":[{"introduced":"0"},{"fixed":"97bf405418d0997717d55e0556045ff80945e099"},{"fixed":"947ff1d33f00f940aa68ae2593500291d799d954"}],"database_specific":{"cpe":"cpe:2.3:a:junrar_project:junrar:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"7.5.8"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v7.5.7","v7.5.6","v7.5.5","v7.5.4","v7.5.3","v7.5.2","v7.5.1","v7.5.0","v7.4.1","v7.4.0","v7.3.0","v7.2.0","v7.1.0","v7.0.0","v6.0.1","v6.0.0","v5.0.0","v4.0.0","junrar-4.0.0","junrar-3.1.1","junrar-3.1.0","junrar-3.0.0","junrar-2.0.0","junrar-1.0.0","junrar-0.7","junrar-0.6"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28208.json","vanir_signatures_modified":"2026-08-12T15:32:09Z","vanir_signatures":[{"target":{"file":"src/main/java/com/github/junrar/LocalFolderExtractor.java","function":"makeFile"},"deprecated":false,"digest":{"function_hash":"255628577017413976390364664209423981913","length":587},"id":"CVE-2026-28208-08374fe6","signature_type":"Function","signature_version":"v1","source":"https://github.com/junrar/junrar/commit/947ff1d33f00f940aa68ae2593500291d799d954"},{"id":"CVE-2026-28208-54e324f0","signature_type":"Line","signature_version":"v1","source":"https://github.com/junrar/junrar/commit/947ff1d33f00f940aa68ae2593500291d799d954","target":{"file":"src/main/java/com/github/junrar/LocalFolderExtractor.java"},"deprecated":false,"digest":{"line_hashes":["88297885329985031566820961650628254830","233401204801917818868002512122788508873","128866767398863764502504338254649123950","86673760356979505759724460320582977058","316293530010119586860179845484460391464","103930249532501861120123282801326411545","304653336562149604774614226793510223918","177004985908707325089190152339842393824","43693651672511506419582617180681485734"],"threshold":0.9}},{"source":"https://github.com/junrar/junrar/commit/947ff1d33f00f940aa68ae2593500291d799d954","target":{"file":"src/test/java/com/github/junrar/LocalFolderExtractorTest.java"},"deprecated":false,"digest":{"line_hashes":["105993957107534337984763986726559288378","20101408839407024359724620722253532659","61347971335668879750236708147439964681","53454567770377211048893831174509685967","264256901644023452723650568572500485716","46253488028046048607957997130125807593","235387323706888458188417499718511257499"],"threshold":0.9},"id":"CVE-2026-28208-6680393a","signature_type":"Line","signature_version":"v1"},{"id":"CVE-2026-28208-9ef49144","signature_type":"Function","signature_version":"v1","source":"https://github.com/junrar/junrar/commit/947ff1d33f00f940aa68ae2593500291d799d954","target":{"file":"src/main/java/com/github/junrar/LocalFolderExtractor.java","function":"createFile"},"deprecated":false,"digest":{"function_hash":"95474942312849181294642381754757883481","length":539}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}