๐Ÿ” CVE Alert

CVE-2026-53970

HIGH 7.5

ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patch URLs without checksum validation. Attackers can intercept or replace downloads for secondary resource and patch paths in shim.rb, injecting attacker-controlled build steps or source tree modifications that execute during source builds via 'zb install --build-from-source' without any integrity warning.

CWE CWE-494
Vendor lucasgelfond
Product zerobrew
Published Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for lucasgelfond zerobrew

Be the first to know when new high vulnerabilities affecting lucasgelfond zerobrew are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

lucasgelfond / ZeroBrew
0 โ‰ค 0.3.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/lucasgelfond/zerobrew github.com: https://github.com/lucasgelfond/zerobrew/commit/89a60b73c7edd6b662e2a085be3d981b6ebeb1aa vulncheck.com: https://www.vulncheck.com/advisories/zerobrew-version-and-prior-missing-checksum-verification-rce-via-shim-rb

Credits

Katriel Moses