Integrity Verification Flaw in ZeroBrew by Lucas Gelfond
CVE-2026-53970

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-53970?

ZeroBrew versions 0.3.1 and earlier are susceptible to a vulnerability due to a lack of integrity verification in the Ruby compatibility shim. This flaw allows attackers to exploit the system by intercepting and replacing downloads from formula resource or URL-based patch URLs. During the build process initiated through 'zb install --build-from-source', malicious content can be injected, enabling arbitrary code execution without any integrity warning being raised, thereby compromising the system’s security.

Affected Version(s)

ZeroBrew 0 <= 0.3.1

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Katriel Moses
.