CVE-2025-52331
WinRAR vulnerability analysis and mitigation

Overview

CVE-2025-52331 is a Cross-Site Scripting (XSS) vulnerability in the "generate report" functionality of Rarlab WinRAR 7.11. The flaw allows attackers to inject malicious HTML tags into generated HTML reports by crafting archive file names without proper input validation, potentially disclosing sensitive user information. It was discovered by Marcin Bobryk and published on November 12, 2025. The vulnerability has a CVSS v3.1 base score of 6.1 (Medium) per NVD, though the researcher's own assessment assigns a local-attack score of 4.4 (Red Hat CVE, GitHub Gist).

Technical details

The root cause is improper neutralization of input during web page generation (CWE-79). WinRAR 7.11's "generate report" feature includes archived file names directly in the output HTML report without sanitization or escaping, allowing an attacker to embed arbitrary HTML or JavaScript tags within a specially crafted archive file name. Exploitation requires the victim to open an archive containing a maliciously named file and then use the "generate report" function, after which the generated HTML report executes the injected script when opened in a browser. The attack vector is local in the researcher's assessment, requiring the victim to interact with a malicious archive (GitHub Gist).

Impact

Successful exploitation can lead to information disclosure, exposing sensitive data such as the victim's computer username, the directory path where the report was generated, and the local IP address. The injected script executes in the context of the locally opened HTML report, limiting the scope primarily to the local user's environment. There is no direct availability impact, and lateral movement potential is low given the local attack nature (GitHub Gist, Red Hat CVE).

Exploitation steps

  1. Craft malicious archive: Create a RAR or ZIP archive containing a file whose name includes malicious HTML/JavaScript, for example: <script>document.write(document.location+' '+navigator.userAgent)</script>.txt.
  2. Deliver the archive: Distribute the crafted archive to the target victim via email, file sharing, or social engineering.
  3. Victim opens archive in WinRAR 7.11: The victim opens the archive using WinRAR 7.11, which displays the maliciously named file.
  4. Victim generates report: The victim uses WinRAR's "generate report" functionality (Tools > Generate Report), which creates an HTML file listing archive contents including the unsanitized file name.
  5. Victim opens the HTML report: When the victim opens the generated HTML report in a browser, the injected script executes, potentially disclosing the computer username, report directory path, and IP address to the attacker (e.g., via an exfiltration beacon if the script is crafted accordingly) (GitHub Gist).

Indicators of compromise

  • File System: Presence of WinRAR-generated HTML report files containing unexpected <script> tags or other HTML markup within file name fields; archive files with unusually named entries containing HTML special characters (<, >, ", ').
  • Logs: Browser history or recently opened files showing WinRAR-generated HTML reports opened from unexpected or temporary directories.
  • Process: Browser processes launched from WinRAR's report output directory making unexpected outbound network connections shortly after a report is opened.

Mitigation and workarounds

The vulnerability is fixed in WinRAR 7.12 beta 1 and later releases. Users should upgrade to WinRAR 7.12 or newer as soon as possible. As a workaround, users should avoid using the "generate report" functionality when working with archives from untrusted sources, and should not open generated HTML reports from unknown archives (GitHub Gist, WinRAR Release Notes).

Community reactions

The vulnerability was discovered and responsibly disclosed by security researcher Marcin Bobryk, who published a detailed description via GitHub Gist. Red Hat has tracked the CVE in their security advisory database. No significant broader media coverage or notable community discussion has been identified beyond standard vulnerability database aggregation (Red Hat CVE, GitHub Gist).

Additional resources


SourceThis report was generated using AI

Related WinRAR vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-8088HIGH8.4
  • WinRAR logoWinRAR
  • cpe:2.3:a:rarlab:winrar
YesYesAug 08, 2025
CVE-2026-14191HIGH7.8
  • WinRAR logoWinRAR
  • cpe:2.3:a:rarlab:winrar
NoYesJul 01, 2026
CVE-2019-25677MEDIUM6.9
  • WinRAR logoWinRAR
  • cpe:2.3:a:rarlab:winrar
NoYesApr 05, 2026
CVE-2025-52331MEDIUM6.1
  • WinRAR logoWinRAR
  • cpe:2.3:a:rarlab:winrar
NoYesNov 12, 2025
CVE-2025-14111LOW1.3
  • WinRAR logoWinRAR
  • rar
NoNoDec 05, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management