CVE-2026-5223

5.3 MEDIUM
Published: May 25, 2026 Modified: June 01, 2026
View on NVD

Description

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry.Β The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

CVSS v3.x Details

0.0 Low Medium High Critical 10.0
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
https://blog.rust-lang.org/2026/05/25/cve-2026-5223/
Source: 986d4109-89ea-491f-99fd-a8e4803919bd
Mitigation Vendor Advisory
https://github.com/rust-lang/cargo/pull/17031
Source: 986d4109-89ea-491f-99fd-a8e4803919bd
Issue Tracking Patch
https://groups.google.com/g/rustlang-security-announcements/c/IB74S7Yksg8
Source: 986d4109-89ea-491f-99fd-a8e4803919bd
Third Party Advisory Mailing List

3 reference(s) from NVD

Quick Stats

CVSS v3 Score
5.3 / 10.0
EPSS (Exploit Probability)
0.4%
33th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

rust-lang