<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>0dayNews — RARLAB / WinRAR</title><description>Vulnerabilities in RARLAB&apos;s WinRAR, the ubiquitous Windows archive utility — bugs here are attractive to attackers because a single malicious archive can compromise any of WinRAR&apos;s hundreds of millions of installs. Combined article + CVE feed for the RARLAB / WinRAR beat.</description><link>https://0daynews.com/</link><language>en-us</language><item><title>CVE-2018-20250 — WinRAR Absolute Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2018-20250/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2018-20250/</guid><description>WinRAR Absolute Path Traversal vulnerability leads to Remote Code Execution</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>RARLAB / WinRAR</category><category>high</category><category>cve</category></item><item><title>CVE-2022-30333 — RARLAB UnRAR Directory Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2022-30333/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2022-30333/</guid><description>RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>RARLAB / WinRAR</category><category>high</category><category>cve</category></item><item><title>CVE-2023-38831 — WinRAR Path Traversal / Spoofed File Extension Code Execution</title><link>https://0daynews.com/cve/cve-2023-38831/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2023-38831/</guid><description>A vulnerability in RARLAB&apos;s WinRAR allows a crafted archive to execute arbitrary code when a user attempts to view what appears to be an innocuous file (e.g. a .jpg) inside the archive — a decoy folder with a matching name masks a malicious script that runs instead.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>RARLAB / WinRAR</category><category>high</category><category>cve</category></item><item><title>CVE-2025-6218 — RARLAB WinRAR Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2025-6218/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-6218/</guid><description>RARLAB WinRAR contains a path traversal vulnerability allowing an attacker to execute code in the context of the current user.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>RARLAB / WinRAR</category><category>high</category><category>cve</category></item><item><title>CVE-2025-8088 — RARLAB WinRAR Path Traversal Vulnerability</title><link>https://0daynews.com/cve/cve-2025-8088/</link><guid isPermaLink="true">https://0daynews.com/cve/cve-2025-8088/</guid><description>RARLAB WinRAR contains a path traversal vulnerability affecting the Windows version of WinRAR. This vulnerability could allow an attacker to execute arbitrary code by crafting malicious archive files.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate><category>RARLAB / WinRAR</category><category>high</category><category>cve</category></item><item><title>WinRAR Bug Hid a Malicious Script in a Fake Photo</title><link>https://0daynews.com/articles/2026-07-05-winrar-path-traversal-cve-2023-38831/</link><guid isPermaLink="true">https://0daynews.com/articles/2026-07-05-winrar-path-traversal-cve-2023-38831/</guid><description>CVE-2023-38831 let a booby-trapped archive execute code when a user clicked what looked like a harmless image file — exploited against trading forums before the technical details were widely known.</description><pubDate>Sun, 05 Jul 2026 13:00:00 GMT</pubDate><category>RARLAB / WinRAR</category><category>article</category></item></channel></rss>