Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41245

27
FAUCET Score

CVE-2026-41245 is a path traversal vulnerability in Junrar, an open-source Java RAR archive library affecting versions prior to 7.5.10. The vulnerability resides in the LocalFolderExtractor component and allows attackers to write arbitrary files with attacker-controlled content into sibling directories when processing a crafted RAR archive. The issue has been resolved in version 7.5.10. The vulnerability carries a CVSS score of 7.5 (HIGH) with a network attack vector that requires no authentication or user interaction, indicating moderate-to-significant risk. While the attack has high integrity impact, it does not compromise confidentiality or system availability. The attack complexity is low, meaning the vulnerability can be exploited straightforwardly. Current exploitation indicators suggest minimal active threat activity. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog and does not appear on the Hot List, indicating no documented active exploitation. The EPSS score of 0.00035 ranks this vulnerability below the 0.1% percentile for exploitation likelihood, suggesting low probability of near-term exploitation despite the moderate CVSS rating.

Impacted Technologies

VendorProductVersion(s)CPE
< 7.5.10CPE matchmatch criteria
cpe:2.3:a:junrar_project:junrar:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.34%
Probability of exploitation in next 30 days
EPSS Percentile
26.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0034 is in the 8th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: com.github.junrar:junrarFixed in: 7.5.10

Vendor Advisories (1)

mavenGHSA-hf5p-q87m-crj7medium

Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix

Apr 16, 2026

References

access.redhat.com / security/cve/CVE-2026-41245
bugzilla.redhat.com / show_bug.cgi
security.access.redhat.com / data/csaf/v2/vex/2026/cve-2026-41245.json
github.com / junrar/junrar/commit/d77e9a83eb721cd51f9c23d7869d0e6ad7f952d7
Patch
github.com / junrar/junrar/releases/tag/v7.5.10
Release Notes
github.com / junrar/junrar/security/advisories/GHSA-hf5p-q87m-crj7
Vendor Advisory