Executive brief
Cargo, the package manager for the Rust programming language, contains a vulnerability that affects users of third-party software registries. A malicious software package could be crafted to overwrite the source code of other packages stored in a developer's local cache. This could lead to the silent inclusion of malicious code in future software builds, potentially compromising the integrity of applications and development environments.
Technical details
A vulnerability exists in Cargo's crate extraction logic where symbolic links (symlinks) within crate tarballs are not properly restricted. While Cargo has protections to prevent extraction outside the crate's cache directory, a crafted tarball can extract files one level below its own directory. This allows an attacker to overwrite the source code of other crates belonging to the same third-party registry within the local `~/.cargo` cache. The attack requires a user to download a malicious crate from a non-crates.io registry (as crates.io already blocks symlinks). The issue is resolved in Cargo version 0.97.0 (shipped with Rust 1.96.0) by rejecting all symlinks during extraction.
Affected products
- Rust Cargo < 0.97.0 (Rust < 1.96.0)
Timeline
- 2026-05-25: advisory: Initial advisory and NVD publication
- 2026-05-28: patched: Rust 1.96.0 released with the fix
- 2026-06-26: other: GitHub Advisory Database entry updated
References
- https://api.github.com/users/christos-spearbit
- https://github.com/christos-spearbit
- https://api.github.com/users/christos-spearbit/gists%7B/gist_id%7D
- https://api.github.com/users/christos-spearbit/repos
- https://avatars.githubusercontent.com/u/265288016?v=4
- https://api.github.com/users/christos-spearbit/events%7B/privacy%7D