PT-2026-65777 · Gnu · Bison

·

CVE-2026-56389

·

Published

2026-07-29

·

Updated

2026-08-24

CVSS v3.1

8.6

High

VectorAV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GNU Bison version 3.8.2
Description Improper handling of grammar-defined configuration variables allows the execution of an arbitrary program during HTML report generation. A grammar file can override the executable used for the XML-to-HTML transformation step via the %define tool.xsltproc configuration, which is accepted without restriction and passed directly to the execvp() function. When the bison --html command is run on an attacker-provided grammar, it enables the execution of an arbitrary program with the privileges of the Bison process.
Recommendations Apply the fix implemented in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b for version 3.8.2.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-94133
CVE-2026-56389
ECHO-5A4D-F9A3-722E
JLSEC-2026-1345
JLSEC-2026-1346
OESA-2026-3304
OESA-2026-3305
OESA-2026-3306
OESA-2026-3307

Affected Products

Bison