CVE-2026-45774Medium▾ Sunlitcompliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves `trestle://` URIs and relative file paths by joining them wi…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 14.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.4%
Last analysed / modified upstream
0.4% → 0.5%
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves trestle:// URIs and relative file paths by joining them with trestle_root and calling .resolve(), but performs no boundary check to ensure the resolved path stays within the trestle workspace. An attacker can craft a malicious OSCAL profile YAML with imports[].href containing path traversal sequences to read arbitrary files from the server filesystem. Versions 3.12.3 and 4.0.3 patch the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
compliance-trestle >= 4.0.0, < 4.0.3compliance-trestle < 3.12.2Patched in:
compliance-trestle 4.0.3compliance-trestle 3.12.2Connected by shared product, vendor, weakness, or advisory.
CVE-2026-46380Medium· 6.7compliance-trestle is a tooling platform for managing compliance as code
CVE-2026-46345High· 8.4compliance-trestle is a tooling platform for managing compliance as code
CVE-2026-54757High· 7.8Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
CVE-2026-46439High· 7.8compliance-trestle is a tooling platform for managing compliance as code
CVE-2026-45725Highcompliance-trestle is a tooling platform for managing compliance as code
CVE-2026-52776HighCompliance-trestle (Trestle) is a tooling platform for managing compliance as code