Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-h47f-gmjp-m7rr
  • PyPI/compliance-trestle
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 2 days ago
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-2425
  • PyPI/compliance-trestle
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI) 13 Jul
  • Fix available
  • Severity - 7.8 (High)
PYSEC-2026-2427
  • PyPI/compliance-trestle
compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem 13 Jul
  • Fix available
  • Severity - 6.7 (Medium)
PYSEC-2026-2423
  • PyPI/compliance-trestle
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal 13 Jul
  • Fix available
  • Severity - 8.4 (High)
PYSEC-2026-2426
  • PyPI/compliance-trestle
compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal 13 Jul
  • Fix available
  • Severity - 5.5 (Medium)
PYSEC-2026-2424
  • PyPI/compliance-trestle
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal 13 Jul
  • Fix available
  • Severity - 7.1 (High)
GHSA-gg2g-p7xc-qqmm
  • PyPI/compliance-trestle
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI) 28 May
  • Fix available
  • Severity - 7.8 (High)
GHSA-w76h-q7c6-jpjp
  • PyPI/compliance-trestle
compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem 28 May
  • Fix available
  • Severity - 6.7 (Medium)
GHSA-4q5v-7g7x-j79w
  • PyPI/compliance-trestle
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal 28 May
  • Fix available
  • Severity - 8.4 (High)
GHSA-mj4x-vf5c-5xg8
  • PyPI/compliance-trestle
compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal 28 May
  • Fix available
  • Severity - 5.5 (Medium)
GHSA-g3vg-vx23-3858
  • PyPI/compliance-trestle
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal 27 May
  • Fix available
  • Severity - 7.1 (High)