CVE-2025-8088

A

path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:rarlab:winrar:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:a:dtsearch:dtsearch:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

30 Oct 2025, 15:50

Type Values Removed Values Added
References () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8088 - () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8088 - US Government Resource

21 Oct 2025, 23:17

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8088 -

21 Oct 2025, 20:20

Type Values Removed Values Added
References
  • {'url': 'https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8088', 'source': '134c704f-9b21-4f2e-91b3-4a467353bcc0'}

21 Oct 2025, 19:21

Type Values Removed Values Added
References
  • () https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-8088 -

16 Sep 2025, 13:53

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-08 12:15

Updated : 2025-10-30 15:50


NVD link : CVE-2025-8088

Mitre link : CVE-2025-8088

CVE.ORG link : CVE-2025-8088


JSON object : View

CWE
CWE-35

Path Traversal: '.../...//'