Rust — Security Advisory for Cargo (CVE-2026-5223)

Security Advisory for Cargo (CVE-2026-5223)

The Rust Security Response Team was notified that Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source…

Security 1
  • Fixed Cargo incorrectly handling symlinks inside of crate tarballs downloaded from third-party registries that could allow a malicious crate to override source files
View original

Upgraded? How did it go?

Discussion