Skip to content

PRP: Detector for WinRAR Path Traversal RCE (CVE-2025-8088) #1135

@wannabemrrobot

Description

@wannabemrrobot
  • Identifier of the vulnerability: CVE-2025-8088
  • Affected software: WinRAR
    I would like to code a static detector to detect this high(CVSS v4 base score: 8.4) impact RCE which is relatively new at the time of this request. This vulnerability affects all windows systems using certain version of WinRAR zip utility. Kindly, let me know if it is okay to start the development.
  • Type of vulnerability: Arbitrary Code Execution(RCE)
  • Resources:
    CVE-2025-8088 Vuln Detail
    Another blog post for reference

Metadata

Metadata

Assignees

No one assigned

    Labels

    Contributor mainPatch Reward Program: The main issue a contributor is working on (top of the contribution queue).PRPPatch Reward Program: This label is added to all PRP related issues for easy filteringPRP:AcceptedPatch Reward Program: This issue has been accepted as a PRP entry.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions