CVE-2026-46439High· 7.8▾ Twilightcompliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 42.9 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 15.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
Last analysed / modified upstream
0.2% → 0.2%
compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the trestle author jinja command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads into data fields (such as SSP documents or Lookup Tables). The vulnerability does not require attacker control of the template itself. Only attacker-controlled input data rendered into a trusted template is required. This distinction is critical: the template author may only intend to render plain text (e.g., Title: {{ ssp.metadata.title }}), but because of the recursive parsing, the data field itself becomes executable. The vulnerability is caused by recursive re-compilation and re-rendering of already-rendered output. Versions 3.12.3 and 4.0.3 patch the issue.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
compliance-trestle < 3.12.2compliance-trestle >= 4.0.0, < 4.0.3Patched in:
compliance-trestle 3.12.2compliance-trestle 4.0.3Connected by shared product, vendor, weakness, or advisory.
CVE-2026-46345High· 8.4compliance-trestle is a tooling platform for managing compliance as code
CVE-2026-54757High· 7.8Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
CVE-2026-46380Medium· 6.7compliance-trestle is a tooling platform for managing compliance as code
CVE-2026-45774Mediumcompliance-trestle is a tooling platform for managing compliance as code
CVE-2026-45725Highcompliance-trestle is a tooling platform for managing compliance as code
CVE-2026-52776HighCompliance-trestle (Trestle) is a tooling platform for managing compliance as code