CVE-2022-48579: RARLAB UnRAR

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

UnRAR before 6.2.3 allows extraction of files outside of the destination folder via symlink chains.

Affected products

  • RARLAB UnRAR: before 6.2.3 (fixed in 6.2.3)

Published 2023-08-07. Last modified 2026-06-17.