Junglewise Threat Intelligence

CVE-2026-46345: compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in

CVE-2026-46345 · Severity: high · CVSS 8.4 · Published 2026-08-17

Technologies: compliance-trestle (PyPI). Vendors: PyPI.

Executive brief

Compliance-trestle is a tool used to manage compliance artifacts. A vulnerability in its template generation component allows an attacker to write or overwrite files anywhere on the system that the user has access to. This could lead to the compromise of automated build systems (CI/CD), unauthorized code execution, or the corruption of sensitive configuration files.

Technical details

A path traversal vulnerability exists in the `trestle author jinja` command within `trestle/core/commands/author/jinja.py`. The `-o/--output` argument fails to properly validate user-supplied paths, including absolute paths and traversal sequences like `../` or `..\`. An attacker can exploit this to write files outside the intended workspace, potentially overwriting sensitive files such as GitHub Actions workflows (`.github/workflows/*.yml`), Git hooks, or shell configuration files (`.bashrc`). This can be achieved with local access and no authentication, running with the privileges of the user executing the command. The issue is fixed in versions 3.12.2 and 4.0.3.

Affected products

  • oscal-compass compliance-trestle >= 4.0.0, < 4.0.3; <= 3.12.1

Timeline

  • 2026-05-27: disclosed
  • 2026-05-28: advisory

References

Related threats