Vulnerability Intelligence Report
Path traversal vulnerability in WinRAR
CVE-2025-8088
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
8.4
HIGH
EPSS Probability:94.55%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-35 ↗CWE-35 Path traversal
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| win.rar GmbH | WinRAR | 0 <= 7.12 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | ESET, spol. s r.o. · Vendor · Slovak Republic |
| Reserved | 2025-07-23T15:35:47 |
| Published | 2025-08-08T11:11:41 |
| Last Updated | 2026-08-11T03:55:29 |
Community Chatter & Buzz