Can unrar Extract Files with Absolute Paths Safely?
This article examines whether the unrar command-line
utility can safely extract archives containing absolute paths or
directory traversal sequences. By default, modern versions of
unrar are designed to neutralize absolute paths to prevent
overwriting critical system files, but historical vulnerabilities and
specific command-line behaviors mean handling untrusted RAR files still
carries inherent security risks.
How unrar Handles Absolute Paths by Default
When an archive contains files stored with absolute paths (such as
/etc/shadow on Linux or C:\Windows\System32 on
Windows), standard implementations of unrar attempt to
sanitize these paths. The utility typically strips leading slashes,
drive letters, and parent directory references (../) before
writing files to the disk. Instead of writing directly to the root
filesystem, it forces extraction relative to the current working
directory or the specified target directory.
Directory Traversal Risks and Past Vulnerabilities
Despite built-in path sanitization, unrar has
historically suffered from path traversal vulnerabilities. A notable
example is CVE-2022-30333, a severe vulnerability in Unix versions of
unrar where malicious actors could bypass path validation
by using symbolic links or specific path formatting. This allowed
attackers to write files outside the intended target directory, leading
to remote code execution on systems that automatically processed email
attachments or user uploads.
Because archive extraction logic is complex, relying entirely on the application's internal filters to block malicious path traversal remains risky if the software is outdated.
Command-Line Switches Affecting Path Safety
The flags passed to unrar significantly alter how paths
are handled:
unrar x(Extract with full paths): Recreates the internal directory structure while attempting to strip root-level markers. This is standard extraction, but it carries the highest exposure to directory-traversal edge cases.unrar e(Extract without paths): Flattens the archive, extracting all files into a single destination folder regardless of their original path structure. This naturally mitigates directory traversal attacks, though it can cause name collisions if files share names across different folders.-epswitch: Excludes paths from the extraction process, serving as an additional layer of protection by forcing all output into the current directory.
Best Practices for Safe Extraction
To safely extract archives that may contain absolute paths or untrusted content:
- Keep unrar Updated: Always run the latest patched version from RARLAB or your operating system's official package repository to protect against known traversal bugs.
- Avoid Running as Root or Administrator: Never
extract untrusted archives with elevated privileges. Running
unrarunder a restricted user account prevents accidental or malicious overwrites of vital system files. - Use Sandboxing or Containers: For automated processing of incoming RAR archives, run the extraction process inside an isolated container, chroot jail, or temporary sandbox with read-only access to the rest of the filesystem.
- Inspect Archives First: Use
unrar lorunrar vto list the archive's contents and inspect internal file paths before executing an extraction command.