THREAT OPS › CVEs › CVE-2025-8088
CVE-2025-8088 — RARLAB WinRAR Path Traversal Vulnerability
RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.
Vulnerability details
- Affected productsWinRAR
- KEV remediation due2025-09-02
Exploiting threat actors
- Indrik SpiderG0119
- Earth LuscaG1006
Related reporting
- Exploits and vulnerabilities in Q2 2026securelist
- [NVD] CVE-2025-8088 (HIGH 8.8) — A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček frnvd
- STOCKSTAY Another Day: The Latest Addition to Turla’s Intelligence Gathering Apparatusmandiant_gti
- June 2026 CVE Landscaperecordedfuture
- 15th June – Threat Intelligence Reportcheckpoint_research