A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarget.java of the component gofmt. The manipulation leads to command injection. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
Affected Vendors & Products
References
History
Sun, 28 Jun 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarget.java of the component gofmt. The manipulation leads to command injection. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
| Title | antlr ANTLR4 gofmt GoTarget.java GoTarget command injection | |
| First Time appeared |
Antlr
Antlr antlr4 |
|
| Weaknesses | CWE-74 CWE-77 |
|
| CPEs | cpe:2.3:a:antlr:antlr4:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Antlr
Antlr antlr4 |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-28T14:30:08.236Z
Reserved: 2026-06-27T18:28:01.063Z
Link: CVE-2026-13501
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-06-28T16:30:17Z