Impact
Junrar’s LocalFolderExtractor can create directories outside the intended extraction root during archive processing. The code validates only the final canonical path but uses unchecked mkdir() calls to create intermediate directories. A crafted RAR entry can therefore cause the library to create an intermediate directory outside the designated extraction directory, leading to filesystem pollution or file‑versus‑directory squatting. While this does not allow unrestricted file content writes, it can break subsequent writes that rely on the existence of a file at that location, potentially causing denial of service or other unpredictable behavior.
Affected Systems
The vulnerability is present in the Junrar open‑source Java library for RAR archives. All releases before version 7.6.1 are affected, with the fix applied starting in 7.6.1. Developers who use Junrar to extract user‑supplied archives are the primary audience.
Risk and Exploitability
The CVSS score of 3.7 marks the issue as low severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to supply a crafted archive and find that Junrar is used in a context with sufficient privileges on the local system; the attack vector is likely local, not remote.
OpenCVE Enrichment
Github GHSA