FAIL › dossier
RARLAB
VENDOR· dossier confidence 20%
RARLAB, a software development company known for its file archivers, has experienced significant security vulnerabilities in its products, highlighting potential weaknesses in its security posture and update processes.
PROFILE
Categorysoftware developmentWhat they doRARLAB develops file archivers, specifically WinRAR and RAR, which are widely used for compressing and extracting files.
Websitehttps://www.rarlab.com/ ↗
SECURITY POSTURE
RARLAB has faced multiple security vulnerabilities, indicating a potential lack of robust security practices and updates.
Notable failures
- CVE-2018-20250
- CVE-2023-38831
- CVE-2022-30333
- CVE-2025-8088
- CVE-2025-6218
Patterns: Repeated unpatched vulnerabilities in file archivers; Lack of auto-updates leading to prolonged exposure to vulnerabilities
FAILURE HISTORY · 5
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2022-02-15 | CVE-2018-20250 | critical | WinRAR's path traversal vulnerability allowed remote code execution and has been actively exploited in ransomware attacks, demonstrating a critical failure to control user input and validate file paths. |
| 2023-08-24 | CVE-2023-38831 | critical | RARLAB WinRAR contained an unpatched code execution vulnerability exploited in the wild by ransomware actors. |
| 2022-08-09 | CVE-2022-30333 | critical | RARLAB UnRAR on Linux/UNIX allows attackers to write arbitrary files during extraction due to a directory traversal vulnerability. |
| 2025-12-09 | CVE-2025-6218 | high | WinRAR RCE |
| 2025-08-12 | CVE-2025-8088 | high | WinRAR RCE due to path traversal |
DOSSIER SOURCES
- Yamazen (TYO:8051) Company Profile & Description - Stock Analysis · stockanalysis.com
- Rocket Lab (RKLB) Company Profile & Description - Stock Analysis · stockanalysis.com
- Peter Beck - Forbes · www.forbes.com
- CVE-2025-60835 | Tenable® · www.tenable.com
- 7-Zip Critical Flaw: Update to 26.02 Now - tbreak.com · tbreak.com
- GitLab Advisory Database (GLAD) · advisories.gitlab.com
Open questions: How has RARLAB addressed the noted security failures? · What are the current security practices at RARLAB?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-23 03:43:15.728734+00:00