Security Advisory for Cargo (CVE-2026-5223)
The Rust Security Response Team was notified that Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source…
Security
- Fixed Cargo incorrectly handling symlinks inside of crate tarballs downloaded from third-party registries that could allow a malicious crate to override source files