UNIX symbolic link following in Cargo - CVE-2026-5223
Published: May 26, 2026
Vulnerability identifier: #VU132304
CSH Severity: Medium
CVSS v4: 6.5 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H]
CVE-ID: CVE-2026-5223
CWE-ID: CWE-61
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a symlink following issue within crates in third party registries. A remote attacker can override the cached source of other crates.
Affected software
Cargo
Fedora
Open SDK for Rust on AIX
rust
Fedora
Open SDK for Rust on AIX
rust
How to mitigate CVE-2026-5223
Install updates from vendor's website.
Cargo - update to 0.97.0
Open SDK for Rust on AIX - addressed in versions 1.92 Fix Pack 3, 1.94 Fix Pack 1
rust - addressed in versions 1.96.0-1.fc43, 1.96.0-1.fc44
Open SDK for Rust on AIX - addressed in versions 1.92 Fix Pack 3, 1.94 Fix Pack 1
rust - addressed in versions 1.96.0-1.fc43, 1.96.0-1.fc44