Skip to content
COOEY

FAIL › dossier

RARLAB

VENDOR

· dossier confidence 20%

RARLAB, a software development company known for its file archivers, has experienced significant security vulnerabilities in its products, highlighting potential weaknesses in its security posture and update processes.

PROFILE
Categorysoftware developmentWhat they doRARLAB develops file archivers, specifically WinRAR and RAR, which are widely used for compressing and extracting files. Websitehttps://www.rarlab.com/ ↗
SECURITY POSTURE

RARLAB has faced multiple security vulnerabilities, indicating a potential lack of robust security practices and updates.

Notable failures
  • CVE-2018-20250
  • CVE-2023-38831
  • CVE-2022-30333
  • CVE-2025-8088
  • CVE-2025-6218
Patterns: Repeated unpatched vulnerabilities in file archivers; Lack of auto-updates leading to prolonged exposure to vulnerabilities
FAILURE HISTORY · 5
DATEEVENTSEVSUMMARY
2022-02-15 CVE-2018-20250 critical WinRAR's path traversal vulnerability allowed remote code execution and has been actively exploited in ransomware attacks, demonstrating a critical failure to control user input and validate file paths.
2023-08-24 CVE-2023-38831 critical RARLAB WinRAR contained an unpatched code execution vulnerability exploited in the wild by ransomware actors.
2022-08-09 CVE-2022-30333 critical RARLAB UnRAR on Linux/UNIX allows attackers to write arbitrary files during extraction due to a directory traversal vulnerability.
2025-12-09 CVE-2025-6218 high WinRAR RCE
2025-08-12 CVE-2025-8088 high WinRAR RCE due to path traversal
Open questions: How has RARLAB addressed the noted security failures? · What are the current security practices at RARLAB?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-23 03:43:15.728734+00:00