Junrar is an open source java RAR archive library. Prior to version 7.5.8, a backslash path traversal vulnerability in LocalFolderExtractor allows an attacker to write arbitrary files with attacker-controlled content anywhere on the filesystem when a crafted RAR archive is extracted on Linux/Unix. This can often lead to remote code execution (e.g., overwriting shell profiles, source code, cron jobs, etc). Version 7.5.8 has a fix for the issue.
{
"cwe_ids": [
"CWE-22"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/28xxx/CVE-2026-28208.json",
"cna_assigner": "GitHub_M"
}{
"cpe": "cpe:2.3:a:junrar_project:junrar:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.5.8"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"2026-08-12T15:32:09Z"
[
{
"id": "CVE-2026-28208-08374fe6",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 587.0,
"function_hash": "255628577017413976390364664209423981913"
},
"source": "https://github.com/junrar/junrar/commit/947ff1d33f00f940aa68ae2593500291d799d954",
"target": {
"function": "makeFile",
"file": "src/main/java/com/github/junrar/LocalFolderExtractor.java"
}
},
{
"id": "CVE-2026-28208-54e324f0",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"88297885329985031566820961650628254830",
"233401204801917818868002512122788508873",
"128866767398863764502504338254649123950",
"86673760356979505759724460320582977058",
"316293530010119586860179845484460391464",
"103930249532501861120123282801326411545",
"304653336562149604774614226793510223918",
"177004985908707325089190152339842393824",
"43693651672511506419582617180681485734"
]
},
"source": "https://github.com/junrar/junrar/commit/947ff1d33f00f940aa68ae2593500291d799d954",
"target": {
"file": "src/main/java/com/github/junrar/LocalFolderExtractor.java"
}
},
{
"id": "CVE-2026-28208-6680393a",
"deprecated": false,
"signature_type": "Line",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"105993957107534337984763986726559288378",
"20101408839407024359724620722253532659",
"61347971335668879750236708147439964681",
"53454567770377211048893831174509685967",
"264256901644023452723650568572500485716",
"46253488028046048607957997130125807593",
"235387323706888458188417499718511257499"
]
},
"source": "https://github.com/junrar/junrar/commit/947ff1d33f00f940aa68ae2593500291d799d954",
"target": {
"file": "src/test/java/com/github/junrar/LocalFolderExtractorTest.java"
}
},
{
"id": "CVE-2026-28208-9ef49144",
"deprecated": false,
"signature_type": "Function",
"signature_version": "v1",
"digest": {
"length": 539.0,
"function_hash": "95474942312849181294642381754757883481"
},
"source": "https://github.com/junrar/junrar/commit/947ff1d33f00f940aa68ae2593500291d799d954",
"target": {
"function": "createFile",
"file": "src/main/java/com/github/junrar/LocalFolderExtractor.java"
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-28208.json"