A security advisory for Cargo detailing a medium-severity vulnerability (CVE-2026-5223) related to symlinks in crate tarballs from third-party registries. Cargo's future update (Rust 1.96.0) will remedy this issue by prohibiting the extraction of symlinks, improving security for users.