CVE-2026-41245
Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted. Version 7.5.10 fixes the issue.
वीकनेस
Junrar is an open source java RAR archive library. Prior to version 7.5.10, a path traversal vulnerability in `LocalFolderExtractor` allows an attacker to write arbitrary files with attacker-controlled content into sibling directories when a crafted RAR archive is extracted. Version 7.5.10 fixes the issue.
प्रभावित प्रोडक्ट
- junrar_project junrar
संदर्भ
- https://github.com/junrar/junrar/commit/d77e9a83eb721cd51f9c23d7869d0e6ad7f952d7
- https://github.com/junrar/junrar/releases/tag/v7.5.10
- https://github.com/junrar/junrar/security/advisories/GHSA-hf5p-q87m-crj7
- https://access.redhat.com/security/cve/CVE-2026-41245
- https://bugzilla.redhat.com/show_bug.cgi?id=2459769
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41245.json
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।