How to Safely Pass Uploaded Files to unrar
Handling user-uploaded archive files on a web server introduces
significant security risks, including remote code execution, directory
traversal (Zip Slip), command injection, and denial-of-service via
decompression bombs. To safely process files with unrar,
you must implement defense-in-depth: decouple the user's input from
system execution, restrict the extraction environment, enforce strict
resource limits, and isolate the binary within a sandbox.
1. Prevent Command Injection
Never invoke unrar through a system shell (such as PHP's
exec, Python's os.system or
subprocess.run(shell=True), or Node's
child_process.exec). Passing unsanitized input to a shell
allows attackers to append arbitrary shell commands.
- Use Direct Process Execution: Pass arguments as an
explicit array or list using functions like
execFile(Node.js) orsubprocess.run([...], shell=False)(Python). - Randomize Stored Filenames: Never pass the original
user-supplied filename to
unrar. Save the upload with a cryptographically secure random name (e.g., a UUID or hash) with no extension or a safe.rarextension. - Disable Options Parsing on Inputs: Place
--before file paths in the CLI command to ensureunrartreats filenames as arguments rather than command-line flags.
Example command structure:
unrar x -p- -idq -- /tmp/uploads/uuid-1234.rar /tmp/unpacked/uuid-1234/2. Defend Against Path Traversal (Directory Traversal)
Malicious archives can contain relative paths (such as
../../etc/cron.d/malicious_task) or absolute paths to
overwrite critical server files.
- Extract to an Isolated Directory: Create a unique, dedicated scratch directory for every extraction task.
- Validate Extracted Paths: After extraction, verify that every extracted file's canonical, resolved path resides inside the designated destination folder. Reject or delete any output that resolves outside the target boundary.
- Flatten Output (If Applicable): If preserving
directory structures is unnecessary, use the
ecommand instead ofxto extract all files into the root destination directory, ignoring internal folder paths.
3. Mitigate Decompression Bombs and Resource Exhaustion
Attackers can upload "RAR bombs"—tiny archives that unpack into gigabytes or terabytes of data—exhausting disk space, memory, and CPU cycles.
- Enforce Process Timeouts: Abort the extraction process if it runs longer than an acceptable threshold (e.g., 10 to 30 seconds).
- Limit Resource Usage: Use system-level controls
such as
prlimit,ulimit, or cgroups to constrain maximum CPU time, memory, and file output size for the process. - Inspect Archive Headers First: Run
unrar l -p- [file]or use an archive library to inspect the declared uncompressed size before extracting. Reject archives where the total extracted size or file count exceeds safe thresholds.
4. Configure Essential unrar Flags
When invoking the CLI, apply restrictive flags to prevent the process from hanging or requesting interactive input:
-p-: Do not query for passwords. If the archive is encrypted, this prevents the process from waiting indefinitely for terminal input.-y: Assume "yes" on all queries (or use-o-to reject overwriting existing files).-idq: Quiet mode; suppresses non-critical output to reduce memory consumption from process stdout buffers.
5. Sandbox the Process
Historically, unrar has suffered from serious
memory-corruption and path-traversal vulnerabilities (such as
CVE-2022-30333). Never run unrar with root or standard web
server privileges (www-data).
- Dedicated User: Execute the binary under an unprivileged user account that has read access only to the temporary archive and write access only to the isolated output folder.
- OS-Level Isolation: Run the extraction process
inside an isolated environment using tools like Docker containers,
nsjail, systemd sandboxing (DynamicUser=true,ProtectSystem=strict), or Firejail. - Drop Network and System Privileges: Deny network access entirely to the extracting process and mount the rest of the filesystem as read-only.
6. Keep Software Updated
Maintain an automated patching pipeline for the unrar
binary. Regularly check for updates and security advisories from
upstream maintainers to patch known vulnerabilities promptly.