Known vulnerability record
CVE-2025-8088
RARLAB WinRAR Path Traversal Vulnerability
Summary
RARLAB WinRAR Path Traversal Vulnerability
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
Signals
Keep the signals separate
CVSS severityhighScore 8.4 · source ESET
EPSS probability94.6%Probability of exploitation in the next 30 days; not severity
CISA KEVKnown exploitedAdded 2025-08-12
Ransomware useknownPreserved as known / unknown, not a truthy default
Timeline
Dates and provenance
- CVE published
- 2025-08-08
- CVE modified
- 2026-08-11
- KEV date added
- 2025-08-12
- Dataset fetched
- 2026-08-21T03:55:05.782Z
Sources
Original records
- https://www.cve.org/CVERecord?id=CVE-2025-8088 ↗
- https://nvd.nist.gov/vuln/detail/CVE-2025-8088 ↗
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8088 ↗
Version history: normalized permanent page created 2026-08-20. Machine-enriched fields remain source-attributed.