← Back to CVE List
Vulnerability Intelligence Report
Path traversal vulnerability in WinRAR

CVE-2025-8088

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
8.4
HIGH
EPSS Probability:94.55%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-35 ↗CWE-35 Path traversal

Affected Products & Versions

Vendor Product Affected Versions
win.rar GmbH WinRAR 0 <= 7.12 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
94.551%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityESET, spol. s r.o. · Vendor · Slovak Republic
Reserved2025-07-23T15:35:47
Published2025-08-08T11:11:41
Last Updated2026-08-11T03:55:29

LINK COPIED TO CLIPBOARD