Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2025-8088— Path traversal vulnerability in WinRAR

Quick assessment

Affected
win.rar GmbH WinRAR
Exploitation
Confirmed exploitation in the wild; remediate immediately
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WinRAR是WinRAR公司的一款文件压缩器。该产品支持RAR、ZIP等格式文件的压缩和解压等。 WinRAR存在安全漏洞,该漏洞源于路径遍历问题,可能导致任意代码执行。

CVSS 8.4 · High KEV · Ransomware EPSS 94.55% · P100

Affected Version Matrix 1

VendorProduct Version RangeStatus
win.rar GmbH WinRAR ≤ 7.12 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2025-8088

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Path traversal vulnerability in WinRAR
Source: CVE Program / CVE List V5
Vulnerability Description
A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
路径遍历:’…/…//’
Source: CVE Program / CVE List V5
Vulnerability Title
WinRAR 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WinRAR是WinRAR公司的一款文件压缩器。该产品支持RAR、ZIP等格式文件的压缩和解压等。 WinRAR存在安全漏洞,该漏洞源于路径遍历问题,可能导致任意代码执行。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Shenlong Deep Dive — AI Deep Analysis

10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.

Affected Products

Vendor Product Affected Versions CPE Subscribe
win.rar GmbH WinRAR 0 ~ 7.12 -

II. Public POCs for CVE-2025-8088

# POC Description Source Link Shenlong Link
1 Python tool for safe archive handling, path traversal awareness, and secure extraction. Inspired by CVE-2025-8088. https://github.com/jordan922/CVE-2025-8088 POC Details
2 cve-2025-8088_detection https://github.com/travisbgreen/cve-2025-8088 POC Details
3 WinRAR 0day CVE-2025-8088 PoC RAR Archive https://github.com/knight0x07/WinRAR-CVE-2025-8088-PoC-RAR POC Details
4 CVE-2025-8088 WinRAR Proof of Concept (PoC-Exploit) https://github.com/sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit- POC Details
5 Advanced WinRAR Path Traversal Exploit Tool for CVE-2025-8088 https://github.com/onlytoxi/CVE-2025-8088-Winrar-Tool POC Details
6 None https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC POC Details
7 Exploit systems using older WinRAR https://github.com/pentestfunctions/CVE-2025-8088-Multi-Document POC Details
8 Proof-of-Concept for CVE-2025-8088 vulnerability in WinRAR (path traversal via ADS) https://github.com/pexlexity/WinRAR-CVE-2025-8088-Path-Traversal-PoC POC Details
9 None https://github.com/Syrins/CVE-2025-8088-Winrar-Tool-Gui POC Details
10 🚀 Demonstrate the WinRAR CVE-2025-8088 exploit with a PoC RAR archive that installs a VBScript on startup, showcasing its impact on vulnerable systems. https://github.com/amel-62/WinRAR-CVE-2025-8088-PoC-RAR POC Details
11 This PoC is for authorized study and testing. CVE-2025-8088 is actively exploited, and misuse may violate laws or cause harm. Update to WinRAR 7.13+ to avoid suspicious RARs. https://github.com/ghostn4444/CVE-2025-8088 POC Details
12 None https://github.com/DeepBlue-dot/CVE-2025-8088-WinRAR-Startup-PoC POC Details
13 POWERSHEL script to check if your device is affected or no https://github.com/pescada-dev/-CVE-2025-8088 POC Details
14 An engaging walkthrough on uncovering, patching, and securing the WinRAR CVE-2025-8088 with a hands-on hacker’s twist. https://github.com/AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal POC Details
15 Winrar CVE exploitation before 7.13 using multiple ADS streams on a single file (Custom PDF implementation) https://github.com/pentestfunctions/best-CVE-2025-8088 POC Details
16 None https://github.com/nyra-workspace/CVE-2025-8088 POC Details
17 A high-performance, memory-safe implementation of the WinRAR CVE-2025-8088 exploit tool, rewritten in Rust for better reliability and performance. https://github.com/kitsuneshade/WinRAR-Exploit-Tool---Rust-Edition POC Details
18 None https://github.com/walidpyh/CVE-2025-8088 POC Details
19 None https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool POC Details
20 WinRAR CVE-2025-8088 exploit tool https://github.com/cozythrill/CVE-2025-8088 POC Details
21 CVE-2025-8088 path traversal tool https://github.com/tartalu/CVE-2025-8088 POC Details
22 A proof-of-concept exploit for WinRAR vulnerability (CVE-2025-8088) affecting versions 7.12 and lower. This tool creates a malicious RAR archive that embeds payloads in Alternate Data Streams (ADS) with path traversal, potentially leading to arbitrary code execution. https://github.com/techcorp/CVE-2025-8088-Exploit POC Details
23 CVE-2025-8088 https://github.com/nhattanhh/CVE-2025-8088 POC Details
24 None https://github.com/Shinkirou789/Cve-2025-8088-WinRar-vulnerability POC Details
25 WinRAR漏洞CVE-2025-8088的payload一键生成工具 https://github.com/hbesljx/CVE-2025-8088-EXP POC Details
26 CVE-2025-8088 path traversal tool https://github.com/Osinskitito499/CVE-2025-8088 POC Details
27 CVE-2025-8088 path traversal tool https://github.com/m4nbun/CVE-2025-8088 POC Details
28 🚨 Exploit WinRAR CVE-2025-8088 with this PoC RAR archive, demonstrating the vulnerability and its impact when executed on the affected software. https://github.com/pablo388/WinRAR-CVE-2025-8088-PoC-RAR POC Details
29 CVE-2025-8088 exploit C++ impl https://github.com/lucyna77/winrar-exploit POC Details
30 CVE-2025-8088 based path traversal tool https://github.com/kyomber/CVE-2025-8088 POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-8088

登录查看更多情报信息。

IV. Related Vulnerabilities

V. Comments for CVE-2025-8088

No comments yet


Leave a comment