Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-5223

Опубликовано: 25 мая 2026
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is medium for users of third-party registries. Users of crates.io are not affected, as crates.io forbids uploading crates containing any symlink.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rust-lang:cargo:*:*:*:*:*:rust:*:*
Версия до 1.96.0 (исключая)

EPSS

Процентиль: 22%
0.00294
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-61

Связанные уязвимости

CVSS3: 5.3
ubuntu
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

CVSS3: 5.3
redhat
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The severity of the vulnerability is **medium** for users of third-party registries. Users of crates.io are **not affected**, as crates.io forbids uploading crates containing any symlink.

msrc
2 месяца назад

Crates in third party registries can override the cached source of other crates

CVSS3: 5.3
debian
2 месяца назад

Cargo incorrectly handled symlinks inside of crate tarballs downloaded ...

github
около 1 месяца назад

Cargo crates in third party registries can override the cached source of other crates

EPSS

Процентиль: 22%
0.00294
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-61