CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-53970

highCVSS 7.5covered by 1 sourcefirst seen 2026-08-14
ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers to execute arbitrary code by substituting malicious content at formula resource or URL-based patch URLs without checksum validation. Attackers can intercept or replace downloads for secondary resource and patch paths in shim.rb, injecting attacker-controlled build steps or source tree modifications that execute during source builds via 'zb install --build-from-source' without any integrity warning.

⚡ Watch CVE-2026-53970

Get an email if CVE-2026-53970 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-53970

CVE.org record

Embed the live status

CVE-2026-53970 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-53970 status](https://www.csirts.com/badge/CVE-2026-53970)](https://www.csirts.com/cve/CVE-2026-53970)