Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4q5v-7g7x-j79w | compliance-trestle - jinja has an Arbitrary File Write via Path Traversal |
Mon, 17 Aug 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oscal-compass
Oscal-compass compliance-trestle |
|
| Vendors & Products |
Oscal-compass
Oscal-compass compliance-trestle |
Mon, 17 Aug 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly validate, `../`, `..\`, or absolute paths. This allows arbitrary file write to attacker-controlled locations. Versions 3.12.3 and 4.0.3 patch the issue. | |
| Title | compliance-trestle - jinja has an Arbitrary File Write via Path Traversal | |
| Weaknesses | CWE-22 CWE-36 CWE-73 |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-17T18:03:44.422Z
Reserved: 2026-05-13T18:37:30.990Z
Link: CVE-2026-46345
No data.
Status : Received
Published: 2026-08-17T18:16:38.393
Modified: 2026-08-17T18:16:38.393
Link: CVE-2026-46345
No data.
OpenCVE Enrichment
Updated: 2026-08-17T20:00:04Z
Github GHSA