A recently uncovered high-risk directory traversal vulnerability, CVE-2025-6218, in WinRAR software poses a grave threat to user data confidentiality. This flaw enables attackers to remotely execute arbitrary code by leveraging malicious compressed files. The vulnerability stems from the manner in which WinRAR processes directory paths within compressed files, earning it a CVSS score of 7.8.
RARLAB has taken action by addressing this issue in the WinRAR v7.12 Beta 1 test version and strongly advises users to upgrade to this secure version promptly. The vulnerability affects WinRAR v7.11 and earlier versions, while Unix and Android versions remain unaffected.