How to Safely Pass Uploaded Files to unrar

Handling user-uploaded archive files on a web server introduces significant security risks, including remote code execution, directory traversal (Zip Slip), command injection, and denial-of-service via decompression bombs. To safely process files with unrar, you must implement defense-in-depth: decouple the user's input from system execution, restrict the extraction environment, enforce strict resource limits, and isolate the binary within a sandbox.

1. Prevent Command Injection

Never invoke unrar through a system shell (such as PHP's exec, Python's os.system or subprocess.run(shell=True), or Node's child_process.exec). Passing unsanitized input to a shell allows attackers to append arbitrary shell commands.

  • Use Direct Process Execution: Pass arguments as an explicit array or list using functions like execFile (Node.js) or subprocess.run([...], shell=False) (Python).
  • Randomize Stored Filenames: Never pass the original user-supplied filename to unrar. Save the upload with a cryptographically secure random name (e.g., a UUID or hash) with no extension or a safe .rar extension.
  • Disable Options Parsing on Inputs: Place -- before file paths in the CLI command to ensure unrar treats filenames as arguments rather than command-line flags.

Example command structure:

unrar x -p- -idq -- /tmp/uploads/uuid-1234.rar /tmp/unpacked/uuid-1234/

2. Defend Against Path Traversal (Directory Traversal)

Malicious archives can contain relative paths (such as ../../etc/cron.d/malicious_task) or absolute paths to overwrite critical server files.

  • Extract to an Isolated Directory: Create a unique, dedicated scratch directory for every extraction task.
  • Validate Extracted Paths: After extraction, verify that every extracted file's canonical, resolved path resides inside the designated destination folder. Reject or delete any output that resolves outside the target boundary.
  • Flatten Output (If Applicable): If preserving directory structures is unnecessary, use the e command instead of x to extract all files into the root destination directory, ignoring internal folder paths.

3. Mitigate Decompression Bombs and Resource Exhaustion

Attackers can upload "RAR bombs"—tiny archives that unpack into gigabytes or terabytes of data—exhausting disk space, memory, and CPU cycles.

  • Enforce Process Timeouts: Abort the extraction process if it runs longer than an acceptable threshold (e.g., 10 to 30 seconds).
  • Limit Resource Usage: Use system-level controls such as prlimit, ulimit, or cgroups to constrain maximum CPU time, memory, and file output size for the process.
  • Inspect Archive Headers First: Run unrar l -p- [file] or use an archive library to inspect the declared uncompressed size before extracting. Reject archives where the total extracted size or file count exceeds safe thresholds.

4. Configure Essential unrar Flags

When invoking the CLI, apply restrictive flags to prevent the process from hanging or requesting interactive input:

  • -p-: Do not query for passwords. If the archive is encrypted, this prevents the process from waiting indefinitely for terminal input.
  • -y: Assume "yes" on all queries (or use -o- to reject overwriting existing files).
  • -idq: Quiet mode; suppresses non-critical output to reduce memory consumption from process stdout buffers.

5. Sandbox the Process

Historically, unrar has suffered from serious memory-corruption and path-traversal vulnerabilities (such as CVE-2022-30333). Never run unrar with root or standard web server privileges (www-data).

  • Dedicated User: Execute the binary under an unprivileged user account that has read access only to the temporary archive and write access only to the isolated output folder.
  • OS-Level Isolation: Run the extraction process inside an isolated environment using tools like Docker containers, nsjail, systemd sandboxing (DynamicUser=true, ProtectSystem=strict), or Firejail.
  • Drop Network and System Privileges: Deny network access entirely to the extracting process and mount the rest of the filesystem as read-only.

6. Keep Software Updated

Maintain an automated patching pipeline for the unrar binary. Regularly check for updates and security advisories from upstream maintainers to patch known vulnerabilities promptly.