Medium severity6.1NVD Advisory· Published Nov 12, 2025· Updated Jun 17, 2026
CVE-2025-52331
CVE-2025-52331
Description
Cross-site scripting (XSS) vulnerability in the generate report functionality in Rarlab WinRAR 7.11, allows attackers to disclose user information such as the computer username, generated report directory, and IP address. The generate report command includes archived file names without validation in the HTML report, which allows potentially malicious HTML tags to be injected into the report. User interaction is required. User must use the "generate report" functionality and open the report.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- gist.github.com/MarcinB44/2150484497c4b34aedf682c9091b14fanvdThird Party Advisory
- www.rarlab.com/rarnew.htmnvdRelease Notes
- www.win-rar.com/whatsnew.htmlnvdRelease Notes
News mentions
0No linked articles in our index yet.