Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-57171
  • github.com/oscal-compass/compliance-trestle
Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345) 25 Aug
  • Fix available
  • Severity - 7.7 (High)
CVE-2026-57170
  • github.com/oscal-compass/compliance-trestle
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439) 25 Aug
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-52776
  • github.com/oscal-compass/compliance-trestle
Trestle URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 25 Aug
  • Fix available
  • Severity - 8.6 (High)
CVE-2026-54757
  • github.com/oscal-compass/compliance-trestle
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data 25 Aug
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-46345
  • github.com/oscal-compass/compliance-trestle
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal 17 Aug
  • Fix available
  • Severity - 8.4 (High)
CVE-2026-46380
  • github.com/oscal-compass/compliance-trestle
compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem 14 Aug
  • Fix available
  • Severity - 6.7 (Medium)
CVE-2026-46439
  • github.com/oscal-compass/compliance-trestle
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI) 14 Aug
  • Fix available
  • Severity - 7.8 (High)
CVE-2026-45774
  • github.com/oscal-compass/compliance-trestle
compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal 13 Aug
  • Fix available
  • Severity - 6.9 (Medium)
CVE-2026-45725
  • github.com/oscal-compass/compliance-trestle
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal 13 Aug
  • Fix available
  • Severity - 7.1 (High)