Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patch URLs without checksum validation. Attackers can intercept or replace downloads for secondary resource and patch paths in shim.rb, injecting attacker-controlled build steps or source tree modifications that execute during source builds via 'zb install --build-from-source' without any integrity warning. | |
| Title | ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb | |
| Weaknesses | CWE-494 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T15:32:29.878Z
Reserved: 2026-06-11T16:07:12.999Z
Link: CVE-2026-53970
No data.
Status : Received
Published: 2026-08-14T16:16:57.073
Modified: 2026-08-14T16:16:57.073
Link: CVE-2026-53970
No data.
OpenCVE Enrichment
Updated: 2026-08-14T16:30:05Z