Unrated severityCISA KEVNVD Advisory· Published Aug 8, 2025· Updated Feb 26, 2026
Path traversal vulnerability in WinRAR
CVE-2025-8088
Description
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.
Affected products
1- win.rar GmbH/WinRARv5Range: 0
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
2- Ghostwriter Targets Ukrainian Government With Geofenced PDF Phishing, Cobalt StrikeThe Hacker News · May 14, 2026
- Exploits and vulnerabilities in Q1 2026Securelist · May 7, 2026