ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patch URLs without checksum validation. Attackers can intercept or replace downloads for secondary resource and patch paths in shim.rb, injecting attacker-controlled build steps or source tree modifications that execute during source builds via 'zb install --build-from-source' without any integrity warning.
Metrics
Affected Vendors & Products
References
History
Tue, 18 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lucasgelfond
Lucasgelfond zerobrew |
|
| Vendors & Products |
Lucasgelfond
Lucasgelfond zerobrew |
Fri, 14 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patch URLs without checksum validation. Attackers can intercept or replace downloads for secondary resource and patch paths in shim.rb, injecting attacker-controlled build steps or source tree modifications that execute during source builds via 'zb install --build-from-source' without any integrity warning. | |
| Title | ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb | |
| Weaknesses | CWE-494 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-08-14T15:32:29.878Z
Updated: 2026-08-18T02:07:35.304Z
Reserved: 2026-06-11T16:07:12.999Z
Link: CVE-2026-53970
Updated: 2026-08-18T02:07:31.313Z
Status : Received
Published: 2026-08-14T16:16:57.073
Modified: 2026-08-18T02:17:27.193
Link: CVE-2026-53970
No data.