PT-2026-43025 · Rust · Cargo

Published

2026-05-25

·

Updated

2026-05-25

·

CVE-2026-5223

CVSS v4.0

6.5

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is medium for users of third-party registries. Users of crates.io are not affected, as crates.io forbids uploading crates containing any symlink.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-5223

Affected Products

Cargo