compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
Summary
| CVE | CVE-2026-46439 |
|---|---|
| State | PUBLISHED |
| Assigner | GitHub_M |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-14 17:18:14 UTC |
| Updated | 2026-08-14 17:18:14 UTC |
| Description | compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads into data fields (such as SSP documents or Lookup Tables). The vulnerability does not require attacker control of the template itself. Only attacker-controlled input data rendered into a trusted template is required. This distinction is critical: the template author may only intend to render plain text (e.g., `Title: {{ ssp.metadata.title }}`), but because of the recursive parsing, the data field itself becomes executable. The vulnerability is caused by recursive re-compilation and re-rendering of already-rendered output. Versions 3.12.3 and 4.0.3 patch the issue. |
Risk And Classification
Primary CVSS: v3.1 7.8 HIGH from [email protected]
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.001770000 probability, percentile 0.074930000 (date 2026-08-16)
Problem Types: CWE-94 | CWE-1336 | CWE-94 CWE-94: Improper Control of Generation of Code ('Code Injection') | CWE-1336 CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 3.1 | CNA | DECLARED | 7.8 | HIGH | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Oscal-compass | Compliance-trestle | affected < 3.12.2 | Not specified |
| CNA | Oscal-compass | Compliance-trestle | affected >= 4.0.0, < 4.0.3 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/oscal-compass/compliance-trestle/commit/7d107b3ac53caca7bde97... | [email protected] | github.com | |
| github.com/oscal-compass/compliance-trestle/security/advisories/GHSA-gg2... | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | github.com | |
| github.com/pypa/advisory-database/tree/main/vulns/compliance-trestle/PYS... | [email protected] | github.com | |
| github.com/oscal-compass/compliance-trestle/commit/247fcce289f60103f3d8e... | [email protected] | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.