Executive brief
A security vulnerability exists in ANTLR4, a widely used tool for processing structured text and programming languages. When generating Go code, the software fails to properly handle certain inputs, which could allow a local user to execute unauthorized commands on the system. This could lead to a compromise of the local machine's integrity and data.
Technical details
A command injection vulnerability exists in ANTLR4 versions up to 4.13.2 within the GoTarget.java file of the Go code generation target. The issue resides in the GoTarget function's interaction with the 'gofmt' component, where improper neutralization of special elements allows for the execution of arbitrary OS commands. This vulnerability is exploitable by a local attacker with low privileges. While an exploit has been disclosed publicly, the vendor has reportedly not responded to the disclosure, and no official patch is currently confirmed.
Affected products
- antlr ANTLR4 up to 4.13.2
Timeline
- 2026-06-28: disclosed: Public disclosure of the vulnerability and exploit code.
- 2026-06-28: advisory: NVD and VulDB published advisory details.