Medium severity5.3NVD Advisory· Published May 25, 2026· Updated Jul 23, 2026
CVE-2026-5223
CVE-2026-5223
Description
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is medium for users of third-party registries. Users of crates.io are not affected, as crates.io forbids uploading crates containing any symlink.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
cargocrates.io | < 0.97.0 | 0.97.0 |
Affected products
2Patches
Vulnerability mechanics
References
7- github.com/rust-lang/cargo/pull/17031nvdIssue TrackingPatchWEB
- blog.rust-lang.org/2026/05/25/cve-2026-5223/nvdMitigationVendor Advisory
- github.com/advisories/GHSA-jq42-7mfv-hm57ghsaADVISORY
- groups.google.com/g/rustlang-security-announcements/c/IB74S7Yksg8nvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-5223ghsaADVISORY
- blog.rust-lang.org/2026/05/25/cve-2026-5223ghsaWEB
- github.com/rust-lang/cargo/security/advisories/GHSA-jq42-7mfv-hm57ghsaWEB
News mentions
0No linked articles in our index yet.