CVE-2026-5223
Published May 25, 2026Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from th…
- evidence mentions
- 4
- Buzz score
- 32.6