CVE-2026-53970: ZeroBrew version 0.3.1 and prior Missing Checksum Verification RCE via shim.rb

Published Aug 14, 2026
·
Updated

ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patch URLs without checksum validation. Attackers can intercept or replace downloads for secondary resource and patch paths in shim.rb, injecting attacker-controlled build steps or source tree modifications that execute during source builds via 'zb install --build-from-source' without any integrity warning.

Affected Software

1 affected component
ZeroBrew<=0.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade ZeroBrew to a version that resolves this vulnerability.

    Fixed in 0.3.1
  2. Compensating control

    For ZeroBrew source builds using 'zb install --build-from-source', mitigate missing integrity checking by preventing network attackers from substituting malicious formula resource content and URL-based patch downloads (e.g., restrict outbound access and/or ensure downloads are retrieved only from trusted sources).

Event History

Aug 14, 2026
CVE Published
via MITRE·03:32 PM
Data Sourced
via MITRE·03:32 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-53970?

CVE-2026-53970 has a severity rating of high, with a CVSS score of 7.5.

2

How do I fix CVE-2026-53970?

To fix CVE-2026-53970, upgrade to ZeroBrew version 0.3.2 or later, which includes the necessary checksum verification.

3

What types of attacks are possible with CVE-2026-53970?

CVE-2026-53970 allows network attackers to execute arbitrary code by injecting malicious content into the application.

4

Which versions of ZeroBrew are affected by CVE-2026-53970?

CVE-2026-53970 affects ZeroBrew version 0.3.1 and all prior versions.

5

Is user interaction required to exploit CVE-2026-53970?

Yes, CVE-2026-53970 requires user interaction, as it exploits URLs that a user must interact with.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203