This might represent a common misconception about PGP. The algorithm preference information is embedded in the PGP identity. It is signed by the certification/signing key. So a downgrade attack would involve breaking the cryptogrphy used for the certification/signing key. CAST5 is not used for certification or signing and has been nowhere close to the start of the preferences for a really long time. Having CAST5 as some sort of last ditch backward compatibility thing is no more of a weakness than the fact that the computer I am using to write this has an MD5 command.
Having said that, what is wrong with CAST5 for PGP application? What does it have to do with a system that is all about signing things?