CVE-2026-45725High▾ Twilightcompliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache fil…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (../). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location outside the intended cache directory, enabling arbitrary file write with attacker-controlled content to the filesystem. Versions 3.12.3 and 4.0.3 patch the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
compliance-trestle >= 4.0.0, < 4.0.3compliance-trestle < 3.12.2Patched in:
compliance-trestle 4.0.3compliance-trestle 3.12.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-46345High· 8.4compliance-trestle is a tooling platform for managing compliance as code
CVE-2026-54757High· 7.8Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
CVE-2026-46380Medium· 6.7compliance-trestle is a tooling platform for managing compliance as code
CVE-2026-45774Mediumcompliance-trestle is a tooling platform for managing compliance as code
CVE-2026-46439High· 7.8compliance-trestle is a tooling platform for managing compliance as code
CVE-2026-52776HighCompliance-trestle (Trestle) is a tooling platform for managing compliance as code