CVE-2025-8088

HIGH KEV RANSOMWARE

Rarlab Winrar < 7.13 - Path Traversal

Title source: rule

Description

A path traversal vulnerability affecting the Windows version of WinRAR allows the attackers to execute arbitrary code by crafting malicious archive files. This vulnerability was exploited in the wild and was discovered by Anton Cherepanov, Peter Košinár, and Peter Strýček from ESET.

Exploits (39)

nomisec WORKING POC 67 stars
by sxyrxyy · client-side
https://github.com/sxyrxyy/CVE-2025-8088-WinRAR-Proof-of-Concept-PoC-Exploit-
nomisec WORKING POC 53 stars
by onlytoxi · client-side
https://github.com/onlytoxi/CVE-2025-8088-Winrar-Tool
nomisec WORKING POC 45 stars
by knight0x07 · poc
https://github.com/knight0x07/WinRAR-CVE-2025-8088-PoC-RAR
nomisec WORKING POC 34 stars
by pentestfunctions · client-side
https://github.com/pentestfunctions/CVE-2025-8088-Multi-Document
nomisec WORKING POC 22 stars
by hexsecteam · client-side
https://github.com/hexsecteam/CVE-2025-8088-Winrar-Tool
nomisec WORKING POC 10 stars
by jordan922 · client-side
https://github.com/jordan922/CVE-2025-8088
nomisec WRITEUP 8 stars
by AdityaBhatt3010 · poc
https://github.com/AdityaBhatt3010/CVE-2025-8088-WinRAR-Zero-Day-Path-Traversal
nomisec WORKING POC 7 stars
by lucyna77 · poc
https://github.com/lucyna77/winrar-exploit
nomisec WORKING POC 7 stars
by pentestfunctions · client-side
https://github.com/pentestfunctions/best-CVE-2025-8088
nomisec WORKING POC 7 stars
by kitsuneshade · client-side
https://github.com/kitsuneshade/WinRAR-Exploit-Tool---Rust-Edition
nomisec WORKING POC 3 stars
by walidpyh · client-side
https://github.com/walidpyh/CVE-2025-8088
nomisec SUSPICIOUS 3 stars
by Syrins · poc
https://github.com/Syrins/CVE-2025-8088-Winrar-Tool-Gui
nomisec WORKING POC 2 stars
by pexlexity · poc
https://github.com/pexlexity/WinRAR-CVE-2025-8088-Path-Traversal-PoC
nomisec WRITEUP 2 stars
by travisbgreen · poc
https://github.com/travisbgreen/cve-2025-8088
nomisec WORKING POC 1 stars
by bigblue-34 · poc
https://github.com/bigblue-34/CVE-2025-8088-WinRAR-Startup-PoC
nomisec WORKING POC 1 stars
by 0xAbolfazl · local
https://github.com/0xAbolfazl/CVE-2025-8088-WinRAR-PathTraversal-PoC
nomisec SCANNER 1 stars
by ilhamrzr · poc
https://github.com/ilhamrzr/RAR-Anomaly-Inspector
nomisec SUSPICIOUS 1 stars
by Markusino488 · poc
https://github.com/Markusino488/cve-2025-8088
nomisec SCANNER 1 stars
by pescada-dev · poc
https://github.com/pescada-dev/-CVE-2025-8088
nomisec WORKING POC 1 stars
by DeepBlue-dot · client-side
https://github.com/DeepBlue-dot/CVE-2025-8088-WinRAR-Startup-PoC
nomisec WORKING POC 1 stars
by Shinkirou789 · poc
https://github.com/Shinkirou789/Cve-2025-8088-WinRar-vulnerability
nomisec WORKING POC
by Ismael-20223 · poc
https://github.com/Ismael-20223/CVE-2025-8088
nomisec NO CODE
by hbesljx · poc
https://github.com/hbesljx/CVE-2025-8088-EXP
gitlab WORKING POC
by patricnilackshan · poc
https://gitlab.com/patricnilackshan/CVE-2025-8088-WinRAR-POC
gitlab WORKING POC
by ThemeHackers · poc
https://gitlab.com/ThemeHackers/CVE-2025-8088-Winrar-Tool
nomisec WORKING POC
by xi0onamdev · poc
https://github.com/xi0onamdev/WinRAR-CVE-2025-8088-Exploitation-Toolkit
nomisec WORKING POC
by nhattanhh · client-side
https://github.com/nhattanhh/CVE-2025-8088
nomisec WORKING POC
by techcorp · client-side
https://github.com/techcorp/CVE-2025-8088-Exploit
github WORKING POC
by papcaii2004 · pythonlocal
https://github.com/papcaii2004/CVE-2025-8088-WinRAR-builder
nomisec WORKING POC
by undefined-name12 · client-side
https://github.com/undefined-name12/CVE-2025-8088-Winrar
nomisec WORKING POC
by IsmaelCosma · remote
https://github.com/IsmaelCosma/CVE-2025-8088
nomisec WORKING POC
by Jessica74016 · poc
https://github.com/Jessica74016/CVE-2025-8088
nomisec WORKING POC
by ghostn4444 · poc
https://github.com/ghostn4444/CVE-2025-8088

Scores

CVSS v3 8.8
EPSS 0.0677
EPSS Percentile 91.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Exploitation Intel

CISA KEV 2025-08-12
VulnCheck KEV 2025-08-08
ENISA EUVD EUVD-2025-23983
Ransomware Use Confirmed

Classification

CWE
CWE-35
Status published

Affected Products (2)

rarlab/winrar < 7.13
dtsearch/dtsearch < 2023.01

Timeline

Published Aug 08, 2025
KEV Added Aug 12, 2025
Tracked Since Feb 18, 2026