Executive brief
A security vulnerability exists in the ANTLR4 Maven Plugin, a tool used by developers to generate code from language grammars during the software build process. The plugin improperly handles certain temporary files, allowing a local attacker or a compromised build process to execute malicious code on the developer's machine or build server. This could lead to a full system takeover, theft of credentials, or disruption of the software development pipeline.
Technical details
The ANTLR4 Maven plugin's `GrammarDependencies.java` component utilizes `ObjectInputStream.readObject()` to deserialize a grammar dependency status file (typically located in the `target/` directory) without implementing an `ObjectInputFilter`. This lack of filtering allows for the instantiation of arbitrary classes present on the Maven classpath, enabling gadget chain attacks (e.g., via CommonsCollections). An attacker with local write access to the build directory—potentially through shared CI caches or compromised local processes—can place a serialized malicious object in the status file. When a user executes `mvn antlr4:antlr4`, the plugin deserializes the file, leading to Remote Code Execution (RCE) in the context of the build user. The vulnerability also involves a Time-of-Check Time-of-Use (TOCTOU) race condition during the file existence check.
Affected products
- antlr ANTLR4 Maven Plugin up to 4.13.2
Timeline
- 2026-05-26: disclosed: Initial vulnerability report date
- 2026-06-28: advisory: NVD/VulDB publication date