Junglewise Threat Intelligence

CVE-2026-5223: Rust Cargo symlink traversal in crate extraction

CVE-2026-5223 · Severity: medium · CVSS 4 · Published 2026-05-25

Technologies: cargo (crates.io). Vendors: crates.io.

Executive brief

Cargo, the package manager for the Rust programming language, contains a vulnerability that affects users of third-party software registries. A malicious software package could be crafted to overwrite the source code of other packages stored in a developer's local cache. This could lead to the silent inclusion of malicious code in future software builds, potentially compromising the integrity of applications and development environments.

Technical details

A vulnerability exists in Cargo's crate extraction logic where symbolic links (symlinks) within crate tarballs are not properly restricted. While Cargo has protections to prevent extraction outside the crate's cache directory, a crafted tarball can extract files one level below its own directory. This allows an attacker to overwrite the source code of other crates belonging to the same third-party registry within the local `~/.cargo` cache. The attack requires a user to download a malicious crate from a non-crates.io registry (as crates.io already blocks symlinks). The issue is resolved in Cargo version 0.97.0 (shipped with Rust 1.96.0) by rejecting all symlinks during extraction.

Affected products

  • Rust Cargo < 0.97.0 (Rust < 1.96.0)

Timeline

  • 2026-05-25: advisory: Initial advisory and NVD publication
  • 2026-05-28: patched: Rust 1.96.0 released with the fix
  • 2026-06-26: other: GitHub Advisory Database entry updated

References

Related threats