Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.5

CVE-2026-13500: ANTLR4 Grammar Action Block Handler Code Injection Risk

CVE-2026-13500
Summary

ANTLR4 users are at risk of code injection attacks if an attacker manipulates certain files. This could happen if an attacker has remote access to the system. It's recommended to update to the latest version of ANTLR4 to fix this issue.

Original title
A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Ha...
Original description
A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Handler. Executing a manipulation can lead to code injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
nvd CVSS2.0 7.5
nvd CVSS3.1 7.3
nvd CVSS4.0 5.5
Vulnerability type
CWE-74 Injection
CWE-94 Code Injection
Published: 28 Jun 2026 · Updated: 23 Jul 2026 · First seen: 28 Jun 2026