How Unrar Handles Directory Traversal Characters

When extracting archives, unrar inspects and sanitizes file paths to prevent directory traversal attacks, commonly known as "Zip Slip" vulnerabilities. Instead of blindly writing files to the locations declared inside a RAR file, modern versions of unrar normalize internal path names, strip leading slashes and drive letters, and neutralize ../ sequences to ensure extracted contents cannot write outside the designated extraction folder.

Path Sanitization and Normalization

Archive formats store relative or absolute file paths as text metadata inside the archive headers. Malicious archives often craft paths such as ../../../../etc/shadow or ..\..\..\Windows\System32\malicious.dll to overwrite sensitive files.

To prevent this, unrar applies strict path validation routines before creating directories or writing files:

  • Removal of Absolute Roots: unrar strips leading slashes (/ or \) as well as Windows drive letters (e.g., C:) from paths. An absolute path such as /usr/bin/tool is converted into a relative path like usr/bin/tool inside the target directory.
  • Neutralization of Parent Directory Tokens (..): During path parsing, unrar collapses redundant relative path elements (such as ./) and checks for .. tokens. If a path attempts to navigate higher than the target destination directory, unrar either removes the traversal tokens, skips the offending file, or halts the extraction with an error.

Directory traversal attacks can also leverage symbolic links (symlinks) to create a link to an external directory (such as /tmp pointing to /etc) and subsequently extract a file through that link.

unrar mitigates symlink-based traversal by:

  1. Tracking the root target directory and verifying that symlink creation does not create shortcuts that point outside the destination.
  2. Refusing to follow intermediate symlinks created during the extraction process if they resolve to an absolute path or escape the target boundary.

Historical Bypasses and Current Hardening

While path sanitization has long been part of unrar, historical security flaws—most notably CVE-2022-30333—demonstrated that edge cases in Unix-like implementations could bypass validation routines. In that vulnerability, specific character sequences and symlink handling allowed remote attackers to bypass path checks and write arbitrary files outside the working directory on Linux systems.

Modern releases of unrar have hardened this behavior:

  • Hard links and symbolic links are strictly validated against canonical target paths.
  • Path canonicalization is performed before any system calls (open(), mkdir(), or symlink()) are executed.
  • Invalid characters, null bytes, and non-canonical path encodings that could mislead the operating system's filesystem APIs are stripped or rejected.

Command-Line Overrides

Users can alter path extraction behavior using specific command-line switches:

  • unrar e (Extract without paths): Ignores all path information entirely, dumping all files directly into the destination directory. This eliminates directory traversal risks by discarding directory tokens completely.
  • unrar x (Extract with full paths): Recreates the stored directory structure, applying the full security parsing and traversal checks to keep the created tree inside the target boundary.
  • -ep3 (Expand paths with drive letters): An administrative switch that explicitly permits full paths, including drive letters. Because this flag intentionally bypasses traversal safety mechanisms, it should only be used with fully trusted archives.