---
id: CVE-2026-57170
title: >-
  Compliance-trestle (Trestle) is a Python SDK and command-line tool for
  managing OSCAL compliance documents
summary: >-
  Compliance-trestle (Trestle) is a Python SDK and command-line tool for
  managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0
  through 4.0.3, the custom Jinja2 include tags mdsection_include and
  md_clean_include re-par…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-94
  - CWE-1336
published: '2026-08-26'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T21:09:13.080'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57170'
references:
  - url: >-
      https://github.com/oscal-compass/compliance-trestle/commit/0f82d19bd42f9cc0f1b3acd7fc3f6dafe3b6ae10
    label: security-advisories@github.com
  - url: >-
      https://github.com/oscal-compass/compliance-trestle/commit/5335ff873a2a68eb7de43df029bea09cadff22fd
    label: security-advisories@github.com
  - url: >-
      https://github.com/oscal-compass/compliance-trestle/security/advisories/GHSA-mr95-65j8-9mxp
    label: security-advisories@github.com
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57170'
  - url: 'https://github.com/oscal-compass/compliance-trestle/pull/2270'
  - url: 'https://github.com/oscal-compass/compliance-trestle/releases/tag/v3.12.4'
  - url: 'https://github.com/oscal-compass/compliance-trestle/releases/tag/v4.1.0'
  - url: 'https://github.com/advisories/GHSA-mr95-65j8-9mxp'
  - url: 'https://github.com/oscal-compass/compliance-trestle'
tags:
  - nvd
  - ghsa
  - pip
  - osv
epss: 0.00235
epssPercentile: 0.12824
ingestedAt: '2026-08-29T21:42:34.028Z'
aliases:
  - GHSA-mr95-65j8-9mxp
ecosystem: pip
vendor: compliance-trestle
product: compliance-trestle
affected:
  - compliance-trestle < 3.12.4
  - 'compliance-trestle >= 4.0.0, < 4.1.0'
patched:
  - compliance-trestle 3.12.4
  - compliance-trestle 4.1.0
---

## Overview

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown file as Jinja2 template code in a non-sandboxed environment, allowing server-side template injection that can lead to arbitrary code execution. The MDSectionInclude and MDCleanInclude tags in Trestle/core/jinja/tags.py pass included file content to Parser(self.environment, ...).parse(), splicing it into the host template's compilation, and the environment is a plain jinja2.Environment rather than a SandboxedEnvironment, so any expressions in the file are evaluated with full access to the usual SSTI gadget chain. Because Trestle's Markdown writers emit OSCAL prose and component-description fields verbatim, applying delimiter neutralization only to parameter tables, attacker-controlled OSCAL data such as a control statement, part prose, or component description containing Jinja2 syntax flows into an included Markdown file and is executed when the include tag re-parses it. This issue is fixed in version 4.1.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-57170)

Affected packages:

- `compliance-trestle < 3.12.4`
- `compliance-trestle >= 4.0.0, < 4.1.0`

Patched in:

- `compliance-trestle 3.12.4`
- `compliance-trestle 4.1.0`

Source: https://github.com/advisories/GHSA-mr95-65j8-9mxp
