---
id: CVE-2022-30333
title: >-
  RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write
  to files during an extract (aka unpack) operation, as demonstrated by creating
  a ~/.ssh/authorized_keys file
summary: >-
  RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write
  to files during an extract (aka unpack) operation, as demonstrated by creating
  a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N'
cwe:
  - CWE-22
  - CWE-22
  - CWE-59
vendor: rarlab
product: unrar
affected:
  - unrar < 6.12
  - debian_linux = 10.0
patched:
  - unrar 6.12
published: '2022-05-09'
updated: '2026-08-04'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-30333'
references:
  - url: >-
      http://packetstormsecurity.com/files/167989/Zimbra-UnRAR-Path-Traversal.html
    label: cve@mitre.org
  - url: 'https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/'
    label: cve@mitre.org
  - url: 'https://lists.debian.org/debian-lts-announce/2023/08/msg00022.html'
    label: cve@mitre.org
  - url: 'https://security.gentoo.org/glsa/202309-04'
    label: cve@mitre.org
  - url: 'https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz'
    label: cve@mitre.org
  - url: 'https://www.rarlab.com/rar_add.htm'
    label: cve@mitre.org
  - url: >-
      http://packetstormsecurity.com/files/167989/Zimbra-UnRAR-Path-Traversal.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://blog.sonarsource.com/zimbra-pre-auth-rce-via-unrar-0day/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2023/08/msg00022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.gentoo.org/glsa/202309-04'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.rarlab.com/rar/rarlinux-x32-612.tar.gz'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.rarlab.com/rar_add.htm'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-30333
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - kev
  - in-the-wild
  - exploit-available
epss: 0.99085
epssPercentile: 0.99932
kev: true
kevDateAdded: '2022-08-09'
kevDueDate: '2022-08-30'
kevRansomware: true
exploited: true
ingestedAt: '2026-08-04T05:36:12.276Z'
exploits:
  github: 5
  githubRepos:
    - 'https://github.com/TheL1ghtVn/CVE-2022-30333-PoC'
    - 'https://github.com/rbowes-r7/unrar-cve-2022-30333-poc'
    - 'https://github.com/aslitsecurity/Zimbra-CVE-2022-30333'
  metasploit:
    - exploit/linux/fileformat/unrar_cve_2022_30333
    - exploit/linux/http/zimbra_unrar_cve_2022_30333
  checkedAt: '2026-09-19T16:22:53.565Z'
exploitAvailable: true
---

## Overview

RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file. NOTE: WinRAR and Android RAR are unaffected.

## Affected

- `unrar < 6.12`
- `debian_linux = 10.0`

## Remediation

Upgrade past the affected range:

- `unrar 6.12`
