Executive brief
ANTLR4 is a widely used tool for processing structured text and programming languages. A security flaw in its grammar handling component allows an attacker to potentially read sensitive files from the system where the tool is running. This could lead to the exposure of configuration data or other private information if the tool processes untrusted grammar files.
Technical details
A path traversal vulnerability (CWE-22) exists in ANTLR4 up to version 4.13.2 within the TokenVocabParser.java component. The issue is located in the getImportedVocabFile function of the tokenVocab Grammar Option Handler. By providing a specially crafted grammar file, a remote attacker can bypass directory restrictions to read arbitrary files on the host system. The exploit is currently public, and as of the advisory date, the vendor has not responded to disclosure attempts.
Affected products
- antlr ANTLR4 up to 4.13.2
Timeline
- 2026-06-28: advisory: NVD publication date
- 2026-06-28: disclosed: Public exploit available via GitHub issue