Description
Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/github/junrar/LocalFolderExtractor.java can create directories outside the intended extraction root when processing a crafted archive entry. LocalFolderExtractor.createFile() validates only the final canonical file path, while LocalFolderExtractor.makeFile() creates intermediate path segments with unchecked mkdir() calls. An entry can therefore make the final path resolve inside the destination while causing intermediate directory creation outside it, enabling filesystem pollution or file-versus-directory squatting that can make later security-sensitive writes fail. The demonstrated impact is directory creation, not unconditional arbitrary file-content write. This issue is fixed in version 7.6.1.
Published: 2026-09-16
Score: 3.7 Low
EPSS: < 1% Very Low
KEV: No
Impact: File System Pollution via Directory Creation Outside Extraction Root
Action: Patch
AI Analysis

Impact

Junrar’s LocalFolderExtractor can create directories outside the intended extraction root during archive processing. The code validates only the final canonical path but uses unchecked mkdir() calls to create intermediate directories. A crafted RAR entry can therefore cause the library to create an intermediate directory outside the designated extraction directory, leading to filesystem pollution or file‑versus‑directory squatting. While this does not allow unrestricted file content writes, it can break subsequent writes that rely on the existence of a file at that location, potentially causing denial of service or other unpredictable behavior.

Affected Systems

The vulnerability is present in the Junrar open‑source Java library for RAR archives. All releases before version 7.6.1 are affected, with the fix applied starting in 7.6.1. Developers who use Junrar to extract user‑supplied archives are the primary audience.

Risk and Exploitability

The CVSS score of 3.7 marks the issue as low severity, and the EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to supply a crafted archive and find that Junrar is used in a context with sufficient privileges on the local system; the attack vector is likely local, not remote.

Generated by OpenCVE AI on September 18, 2026 at 02:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Junrar to version 7.6.1 or later, which removes the unchecked intermediate directory creation.
  • If upgrading is not immediately possible, add a runtime check to ensure that the canonicalized extraction path resides within the intended root before any directory creation.
  • Audit any custom archive‑extraction code to validate that no path manipulation can result in a directory outside the expected extraction directory, applying the same canonicalization and boundary checks used in the patched library.

Generated by OpenCVE AI on September 18, 2026 at 02:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-89m4-43j5-vhhx Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root
History

Fri, 18 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
First Time appeared Junrar
Junrar junrar
Vendors & Products Junrar
Junrar junrar

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 19:15:00 +0000

Type Values Removed Values Added
Description Junrar is an open source Java RAR archive library. Prior to version 7.6.1, LocalFolderExtractor in src/main/java/com/github/junrar/LocalFolderExtractor.java can create directories outside the intended extraction root when processing a crafted archive entry. LocalFolderExtractor.createFile() validates only the final canonical file path, while LocalFolderExtractor.makeFile() creates intermediate path segments with unchecked mkdir() calls. An entry can therefore make the final path resolve inside the destination while causing intermediate directory creation outside it, enabling filesystem pollution or file-versus-directory squatting that can make later security-sensitive writes fail. The demonstrated impact is directory creation, not unconditional arbitrary file-content write. This issue is fixed in version 7.6.1.
Title Junrar: LocalFolderExtractor mkdir escape allows directory creation outside extraction root
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-17T19:25:35.128Z

Reserved: 2026-09-04T19:34:03.100Z

Link: CVE-2026-86071

cve-icon Vulnrichment

Updated: 2026-09-17T17:10:37.389Z

cve-icon NVD

Status : Deferred

Published: 2026-09-16T19:17:58.623

Modified: 2026-09-24T21:25:27.050

Link: CVE-2026-86071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T03:15:01Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')