Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 17 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Lucasgelfond
Lucasgelfond zerobrew |
|
| Vendors & Products |
Lucasgelfond
Lucasgelfond zerobrew |
Fri, 14 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patch URLs without checksum validation. Attackers can intercept or replace downloads for secondary resource and patch paths in shim.rb, injecting attacker-controlled build steps or source tree modifications that execute during source builds via 'zb install --build-from-source' without any integrity warning. | |
| Title | ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb | |
| Weaknesses | CWE-494 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-18T02:07:35.304Z
Reserved: 2026-06-11T16:07:12.999Z
Link: CVE-2026-53970
Updated: 2026-08-18T02:07:31.313Z
Status : Received
Published: 2026-08-14T16:16:57.073
Modified: 2026-08-18T02:17:27.193
Link: CVE-2026-53970
No data.
OpenCVE Enrichment
Updated: 2026-08-17T11:01:13Z