CVE-2026-56389 | GNU Bison HTML Report Generation execvp tool.xsltproc command injection (EUVD-2026-50276)

SecurityVulns

A vulnerability, which was classified as critical, has been found in GNU Bison. This affects the function execvp of the component HTML Report Generation. This manipulation of the argument tool.xsltproc causes command injection.

This vulnerability appears as CVE-2026-56389. The attack may be initiated remotely. There is no available exploit.

Applying a patch is the recommended action to fix this issue.VulDB Recent EntriesRead More