PT-2026-72043 · Zerobrew · Zerobrew
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ZeroBrew versions prior to 0.3.2
Description
A missing integrity verification in the Ruby compatibility shim allows network attackers to execute arbitrary code. By substituting malicious content at formula resource or URL-based patch URLs, attackers can bypass checksum validation. This occurs when downloads for secondary resource and patch paths in
shim.rb are intercepted or replaced, allowing the injection of attacker-controlled build steps or source tree modifications. These modifications execute during source builds performed via the zb install --build-from-source command without triggering an integrity warning.Recommendations
Update ZeroBrew to version 0.3.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zerobrew