Compliance-trestle(Trestle)是一个用于管理 OSCAL 合规文档的 Python SDK 和命令行工具。在 3.12.4 之前的版本,以及 4.0.0 至 4.0.3 版本中,自定义的 Jinja2 包含标签 和 会将已包含的 Markdown 文件内容重新解析为 Jinja2 模板代码,且该操作在一个未沙盒化(non-sandboxed)的环境中执行。这可能导致服务端模板注入(SSTI),进而引发任意代码执行。 具体而言, 中的 和 标签会将包含的文件内容传递给 ,并将其拼接到宿主模板的
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| oscal-compass | compliance-trestle | < 3.12.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-52776 | 8.6 HIGH | Trestle URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 |
| CVE-2026-54757 | 7.8 HIGH | Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of |
| CVE-2026-57171 | 7.7 HIGH | Trestle is vulnerable to arbitrary file write via path traversal in author generate comman |
No comments yet