CVE-2026-41245 is a path traversal vulnerability in Junrar, an open-source Java RAR archive library affecting versions prior to 7.5.10. The vulnerability resides in the LocalFolderExtractor component and allows attackers to write arbitrary files with attacker-controlled content into sibling directories when processing a crafted RAR archive. The issue has been resolved in version 7.5.10. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network attack vector that requires no authentication or user interaction, indicating moderate-to-significant risk. While the attack has high integrity impact, it does not compromise confidentiality or system availability. The attack complexity is low, meaning the vulnerability can be exploited straightforwardly. Current exploitation indicators suggest minimal active threat activity. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and does not appear on the Hot List, indicating no documented active exploitation. The EPSS score of 0.00035 ranks this vulnerability below the 0.1% percentile for exploitation likelihood, suggesting low probability of near-term exploitation despite the moderate CVSS rating.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 7.5.10CPE matchmatch criteria | cpe:2.3:a:junrar_project:junrar:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.