Integrity Verification Flaw in ZeroBrew by Lucas Gelfond
CVE-2026-53970
7.5HIGH
What is CVE-2026-53970?
ZeroBrew versions 0.3.1 and earlier are susceptible to a vulnerability due to a lack of integrity verification in the Ruby compatibility shim. This flaw allows attackers to exploit the system by intercepting and replacing downloads from formula resource or URL-based patch URLs. During the build process initiated through 'zb install --build-from-source', malicious content can be injected, enabling arbitrary code execution without any integrity warning being raised, thereby compromising the system’s security.
Affected Version(s)
ZeroBrew 0 <= 0.3.1
