CVE-2025-8088
Path traversal vulnerability in WinRAR
Basic Information
- CVE State
- PUBLISHED
- Reserved Date
- July 23, 2025
- Published Date
- August 08, 2025
- Last Updated
- February 26, 2026
- Vendor
- win.rar GmbH
- Product
- WinRAR
- Description
- A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.
- Tags
- Exploitation
- active
- Technical Impact
- total
- Exploited in the Wild
- Yes (2026-06-01 10:38:35 UTC) Source
cisa
CVSS Scores
CVSS v4.0
8.4 - HIGH
Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
SSVC Information
Exploit Status
Known Exploited Vulnerability Information
| Source | Added Date |
|---|---|
| CVE | 2026-06-01 10:38:35 UTC |
Timeline
-
CVE ID Reserved
-
CVE Published to Public
-
Added to KEVIntel