CVE-2026-41245: Junrar: Path Traversal (Zip-Slip) via Sibling Directory Name Prefix
Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted. Version 7.5.10 fixes the issue.
Security readout for executives and security teams
Plain-English summary
Junrar versions before 7.5.10 can let a malicious RAR archive place files outside the intended extraction folder, specifically into sibling directories. If a business process extracts untrusted RAR files, an attacker could overwrite or plant files and disrupt systems or alter application behavior.
Executive priority
Treat as urgent where Junrar processes external or partner-supplied archives. Prioritize internet-facing upload and ingestion systems first, then internal automation. Systems that do not extract untrusted RAR files have lower practical urgency.
Technical view
CVE-2026-41245 is a CWE-22 path traversal in Junrar LocalFolderExtractor. The source bundle describes a Zip-Slip style flaw where crafted archive paths bypass intended directory boundaries via sibling directory name prefixes. Junrar 7.5.10 fixes the issue. CVSS is 9.3 critical with high integrity and availability impact.
Likely exposure
Exposure applies to Java applications or backend workflows using junrar below 7.5.10 to extract attacker-controlled RAR archives. Likely locations include upload processing, content ingestion, email attachment handling, document pipelines, and automated archive unpacking jobs.
Exploitation context
The bundle does not show CISA KEV listing or active exploitation evidence. Exploitation requires a crafted RAR archive to be extracted by a vulnerable application or workflow, so risk depends on whether untrusted archives reach Junrar extraction paths.
Researcher notes
The evidence identifies upstream Junrar before 7.5.10 and a fixed release. The bundle does not provide exploit code, active exploitation confirmation, or detailed downstream Red Hat impact. Validate dependency reachability before declaring business exposure.
Mitigation direction
Upgrade junrar to version 7.5.10 or later.
Identify and patch transitive junrar dependencies in Java builds.
Restrict or pause extraction of untrusted RAR files until upgraded.
Ensure extraction output directories are isolated from application and system paths.
Check upstream and Red Hat guidance for downstream package status.
Validation and detection
Search SBOMs and dependency manifests for junrar versions below 7.5.10.
Confirm production runtime artifacts include the fixed junrar version.
Review upload and ingestion workflows for untrusted RAR extraction.
Verify extraction outputs cannot affect application, web, or operational directories.
Monitor vendor advisories for downstream distribution impact.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · medium confidence lookup
CWE-22: File access and web shell behavior lookup
File traversal and upload weaknesses can lead teams to review file, web shell, execution, and collection telemetry. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
The CVE wording references file access or upload behavior, so file telemetry and web shell review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
CWE-22 · source CWE mapping
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.