How Unrar Handles Destination Symlinks

When extracting archives, unrar employs strict security checks to determine how it interacts with symbolic links in the destination path. This article examines how unrar validates extraction paths, resolves pre-existing symlinks, mitigates path traversal vulnerabilities (such as "Zip Slip"), and enforces security boundaries to prevent unauthorized file overwrites.

Canonical Path Resolution and Jail Checks

Modern versions of unrar enforce extraction boundaries to ensure that extracted contents remain strictly within the intended destination directory. Before writing any file to disk, the utility verifies the canonical path of the target location.

If the base destination path provided in the command line contains or ends with a symlink, unrar typically resolves the symlink to its target directory on the host filesystem and proceeds with extraction, provided the user has write permissions in the target location. However, problems arise when paths inside the archive resolve through symlinks to locations outside the root extraction folder.

Protection Against Arbitrary File Overwrites

Historically, archive utilities were vulnerable to directory traversal attacks where an archive would create a symlink pointing to an absolute path (such as /etc or /usr/bin), followed by a standard file that wrote into that symlink path.

To mitigate this attack vector:

  • Intermediate Symlink Validation: As unrar creates subdirectories and files, it inspects each path component. If a path segment points to a symlink that leads outside the extraction root, unrar treats the operation as insecure.
  • Refusal to Follow Traversal Links: If an archive contains a symlink pointing to an external directory, subsequent files in the archive that attempt to extract through that symlink path are blocked. The extraction will fail with an error or skip the affected files.
  • Overwrite Protections: By default, unrar will not blindly follow an existing symlink to overwrite a target file outside the working directory tree unless explicit flags are supplied to permit overwriting.

The behavior of unrar also depends on how links are encoded within the archive and which command-line switches are invoked:

  • Default Behavior: Symlinks stored within the archive are extracted as symbolic links on platforms that support them (such as Linux and macOS), assuming user permissions allow link creation.
  • The -ol Switch: Instructs unrar to save symbolic links as links rather than writing the contents of the files they reference.
  • Absolute Path Stripping: By default, unrar strips drive letters and leading path separators (such as / or C:\) to prevent archives from defining root-level destinations directly.

If a pre-existing symbolic link exists inside the extraction directory prior to running the utility, unrar checks whether writing through that link compromises the root boundary. If the link points to a location outside the extraction target, unrar detects the breakout attempt, halts writing to that specific path, and reports an error to prevent potential system compromise.