Security: oscal-compass/compliance-trestle
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Incomplete fix of CVE-2026-46345: Path Traversal Arbitrary File Write in trestle author {catalog,profile,ssp}-generate output pathsGHSA-r4vp-3vw6-r2x5 published
Aug 4, 2026 by degenaroHigh -
Incomplete fix of CVE-2026-46439: SSTI / RCE via mdsection_include / md_clean_include re-parse in a non-sandboxed Jinja environmentGHSA-mr95-65j8-9mxp published
Aug 4, 2026 by degenaroHigh -
Server-Side Template Injection (SSTI) — Recursive Template Re-evaluation of Untrusted DataGHSA-jw39-3688-r4rx published
Aug 4, 2026 by degenaroHigh -
compliance-trestle URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0GHSA-h47f-gmjp-m7rr published
Aug 4, 2026 by degenaroHigh -
Remote Code Execution via Recursive Server-Side Template Injection (SSTI)GHSA-gg2g-p7xc-qqmm published
May 27, 2026 by degenaroHigh -
Arbitrary File Write via Path Traversal in compliance-trestle - jinjaGHSA-4q5v-7g7x-j79w published
May 27, 2026 by degenaroHigh -
Arbitrary File Write via Cache Path Traversal in compliance-trestle Remote FetchingGHSA-g3vg-vx23-3858 published
May 27, 2026 by degenaroHigh -
Arbitrary File Read via trestle:// URI and Relative Path Traversal in compliance-trestle Profile ImportGHSA-mj4x-vf5c-5xg8 published
May 27, 2026 by degenaroModerate -
Critical SSRF (CWE-918)GHSA-w76h-q7c6-jpjp published
May 27, 2026 by degenaroModerate