CVE-2026-56389: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in GNU Bison
GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
AI Analysis
Technical Summary
GNU Bison improperly neutralizes special elements used in an OS command during HTML report generation. Specifically, the %define tool.xsltproc configuration variable in a grammar file can override the executable used for the XML-to-HTML transformation step. This value is passed directly to execvp() without validation, enabling an attacker to execute arbitrary commands with the privileges of the Bison process when running 'bison --html' on a malicious grammar file. The vulnerability was fixed in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b, but the vendor did not specify the affected version range. Version 3.8.2 is confirmed vulnerable.
Potential Impact
An attacker who can supply a malicious grammar file to the 'bison --html' command can execute arbitrary code with the privileges of the Bison process. This could lead to unauthorized code execution on the host system. The vulnerability requires local access or the ability to run Bison with attacker-controlled input. The CVSS 4.0 score is 6.8 (medium severity), reflecting the need for user interaction and local access but with high impact on confidentiality and integrity.
Mitigation Recommendations
A fix for this vulnerability exists in the form of commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, the vendor has not provided an official patched version number. Users should update Bison to the latest version that includes this commit once it is officially released. Until then, avoid running 'bison --html' on untrusted grammar files to prevent exploitation.
CVE-2026-56389: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in GNU Bison
Description
GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
CVSS v4.0
Score 6.8medium
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
GNU Bison improperly neutralizes special elements used in an OS command during HTML report generation. Specifically, the %define tool.xsltproc configuration variable in a grammar file can override the executable used for the XML-to-HTML transformation step. This value is passed directly to execvp() without validation, enabling an attacker to execute arbitrary commands with the privileges of the Bison process when running 'bison --html' on a malicious grammar file. The vulnerability was fixed in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b, but the vendor did not specify the affected version range. Version 3.8.2 is confirmed vulnerable.
Potential Impact
An attacker who can supply a malicious grammar file to the 'bison --html' command can execute arbitrary code with the privileges of the Bison process. This could lead to unauthorized code execution on the host system. The vulnerability requires local access or the ability to run Bison with attacker-controlled input. The CVSS 4.0 score is 6.8 (medium severity), reflecting the need for user interaction and local access but with high impact on confidentiality and integrity.
Mitigation Recommendations
A fix for this vulnerability exists in the form of commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, the vendor has not provided an official patched version number. Users should update Bison to the latest version that includes this commit once it is officially released. Until then, avoid running 'bison --html' on untrusted grammar files to prevent exploitation.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- CERT-PL
- Date Reserved
- 2026-06-21T07:15:13.879Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a69d4879c2644c7f856ba7e
Added to database: 07/29/2026, 10:23:03 UTC
Last enriched: 07/29/2026, 10:39:14 UTC
Last updated: 07/29/2026, 21:34:01 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.