← Global Threat Landscape

CVE-2025-6218

CWE-22

Low

44.9

RPS

Description

RARLAB WinRAR Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of RARLAB WinRAR. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of file paths within archive files. A crafted file path can cause the process to traverse to unintended directories. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-27198.

Source: NVD

Signals

CVSS
Not scored
Unknown
EPSS
90.47%
Probability of exploitation in the next 30 days (FIRST)
CISA KEV
In CISA KEV since Dec 2025
Fix commit
No known fix commit
Sources: MoreFixes, FreshFixes
Weakness
CWE-22
Published
21 Jun 2025
Last modified 10 Dec 2025

How to read these signals: RPS · EPSS · CISA KEV · Data sources

Get this score from the API

curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
  https://api.intelligence.devsecure.io/api/v1/rps/CVE-2025-6218

Replace the placeholder with your key. Get a free API key or rank your own CVEs.

Data as of 7 Oct 2026, 05:16 UK time

CVE-2025-6218 · RPS 44.9 · DevSecure Intelligence