ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patch URLs without checksum validation. Attackers can intercept or replace downloads for secondary resource and patch paths in shim.rb, injecting attacker-controlled build steps or source tree modifications that execute during source builds via 'zb install --build-from-source' without any integrity warning.
Metrics
Affected Vendors & Products
References
History
Fri, 14 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patch URLs without checksum validation. Attackers can intercept or replace downloads for secondary resource and patch paths in shim.rb, injecting attacker-controlled build steps or source tree modifications that execute during source builds via 'zb install --build-from-source' without any integrity warning. | |
| Title | ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb | |
| Weaknesses | CWE-494 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T15:32:29.878Z
Reserved: 2026-06-11T16:07:12.999Z
Link: CVE-2026-53970
No data.
Status : Received
Published: 2026-08-14T16:16:57.073
Modified: 2026-08-14T16:16:57.073
Link: CVE-2026-53970
No data.
OpenCVE Enrichment
Updated: 2026-08-14T16:30:05Z