VDB

GCVE-110-BREW-2026-001219

GCVE-110-BREW-2026-001219
Advisory Published
Vulnetix · Advisory published September 4, 2026
The Homebrew cask `loom` (tap homebrew/cask) was flagged as malicious by automated formula analysis (1 corroborating detection(s)). Installing it may execute attacker-controlled code. Verdict path: evidence — for ownership-only paths (owner-known-bad / multi-identity) the change of ownership is a compounding indicator the engine correlated with other signals, not standalone proof. This verdict is produced by static analysis and is subject to human review.

Weaknesses (CWE)

CWE-506Embedded Malicious Code

Affected Products

VendorProductVersionsPlatforms
homebrewloom0.359.0 (affected), 0.368.3 (affected), 0.373.2 (affected)

References

web
advisory
web
web
web
web
web
web

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›