vulns.co
/
GKData.io MCP

Back to CVEs

CVE-2025-8088 - WinRAR for Windows path traversal

A crafted archive can use path traversal to place files outside the intended extraction directory and lead to arbitrary code execution. The CNA record reports exploitation in the wild.

Tags: path-traversal, archive, rce, winrar, exploited

Product
win.rar GmbH WinRAR for Windows through 7.12
Severity
high (CVSS 8.4)
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Published / added
2025-08-08
Signals
CISA KEV

References and evidence