Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

CVE-2026-56389: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in GNU Bison

0
Medium
VulnerabilityCVE-2026-56389cvecve-2026-56389cwe-78
Published: 07/29/2026 (07/29/2026, 09:39:52 UTC)
Source: CVE Database V5
Vendor/Project: GNU
Product: Bison

Description

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

CVSS v4.0

Score 6.8medium

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
Active
Vuln. Confidentiality
None
Vuln. Integrity
High
Vuln. Availability
Low
Subsq. Confidentiality
Low
Subsq. Integrity
Low
Subsq. Availability
Low
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:L/SC:L/SI:L/SA:L

Affected software

Affected versions
3.8.2

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/29/2026, 10:39:14 UTC

Technical Analysis

GNU Bison improperly neutralizes special elements used in an OS command during HTML report generation. Specifically, the %define tool.xsltproc configuration variable in a grammar file can override the executable used for the XML-to-HTML transformation step. This value is passed directly to execvp() without validation, enabling an attacker to execute arbitrary commands with the privileges of the Bison process when running 'bison --html' on a malicious grammar file. The vulnerability was fixed in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b, but the vendor did not specify the affected version range. Version 3.8.2 is confirmed vulnerable.

Potential Impact

An attacker who can supply a malicious grammar file to the 'bison --html' command can execute arbitrary code with the privileges of the Bison process. This could lead to unauthorized code execution on the host system. The vulnerability requires local access or the ability to run Bison with attacker-controlled input. The CVSS 4.0 score is 6.8 (medium severity), reflecting the need for user interaction and local access but with high impact on confidentiality and integrity.

Mitigation Recommendations

A fix for this vulnerability exists in the form of commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, the vendor has not provided an official patched version number. Users should update Bison to the latest version that includes this commit once it is officially released. Until then, avoid running 'bison --html' on untrusted grammar files to prevent exploitation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
CERT-PL
Date Reserved
2026-06-21T07:15:13.879Z
Cvss Version
4.0
State
PUBLISHED
Remediation Level
null

Threat ID: 6a69d4879c2644c7f856ba7e

Added to database: 07/29/2026, 10:23:03 UTC

Last enriched: 07/29/2026, 10:39:14 UTC

Last updated: 07/29/2026, 21:34:01 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses