Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in LocalFolderExtractor allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted. Version 7.5.10 fixes the issue.
{
"cwe_ids": [
"CWE-22"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41245.json"
}{
"source": [
"CPE_RANGE",
"REFERENCES"
],
"cpe": "cpe:2.3:a:junrar_project:junrar:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "7.5.10"
}
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-41245.json"
[
{
"signature_type": "Function",
"digest": {
"function_hash": "92107731362539582230267104099833203232",
"length": 469.0
},
"target": {
"function": "createDirectory",
"file": "src/main/java/com/github/junrar/LocalFolderExtractor.java"
},
"source": "https://github.com/junrar/junrar/commit/d77e9a83eb721cd51f9c23d7869d0e6ad7f952d7",
"signature_version": "v1",
"id": "CVE-2026-41245-04de47ca",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"153992386012682792346819052592366445884",
"75088917877996100587902514741239251625",
"78140208533450940885152221681361601036",
"295148385260240902059232304945752550601",
"135332052916125046971439096908422156140",
"304025772555183256378562013073299057604",
"250947539658484556011468833209322375541",
"220286456496437594070456542686043549090"
]
},
"target": {
"file": "src/main/java/com/github/junrar/LocalFolderExtractor.java"
},
"source": "https://github.com/junrar/junrar/commit/d77e9a83eb721cd51f9c23d7869d0e6ad7f952d7",
"signature_version": "v1",
"id": "CVE-2026-41245-c5201a0c",
"deprecated": false
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"108338963622705630321835909338863966464",
"91846235918049093707165224030728451185"
]
},
"target": {
"file": "src/test/java/com/github/junrar/LocalFolderExtractorTest.java"
},
"source": "https://github.com/junrar/junrar/commit/d77e9a83eb721cd51f9c23d7869d0e6ad7f952d7",
"signature_version": "v1",
"id": "CVE-2026-41245-fe3559aa",
"deprecated": false
},
{
"signature_type": "Function",
"digest": {
"function_hash": "1368334378836099302774862828418556480",
"length": 552.0
},
"target": {
"function": "createFile",
"file": "src/main/java/com/github/junrar/LocalFolderExtractor.java"
},
"source": "https://github.com/junrar/junrar/commit/d77e9a83eb721cd51f9c23d7869d0e6ad7f952d7",
"signature_version": "v1",
"id": "CVE-2026-41245-fe558cad",
"deprecated": false
}
]
"2026-08-20T10:17:13Z"