PatchSiren cyber security CVE debrief
CVE-2026-46345 oscal-compass CVE debrief
CVE-2026-46345 is a high-severity vulnerability in the compliance-trestle tooling platform used for managing compliance as code. An attacker can exploit this issue to write files outside the intended workspace, potentially leading to arbitrary file writes. The vulnerability is due to improper validation of the `-o/--output` argument in `trestle author jinja`, allowing an attacker to write files to attacker-controlled locations. This could result in disruptions to compliance-trestle functionality and potential impacts on data integrity and confidentiality. The vulnerability has a CVSS score of 8.4 and is patched in versions 3.12.3 and 4.0.3.
- Vendor
- oscal-compass
- Product
- compliance-trestle
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-17
- Original CVE updated
- 2026-09-18
- Advisory published
- 2026-08-17
- Advisory updated
- 2026-09-18
Who should care
Defenders responsible for managing compliance as code with compliance-trestle should assess exposure and prioritize patching or mitigating this vulnerability. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. They should also plan vendor-supported updates or mitigations through normal change control where exposure is confirmed and review compensating controls for exposed systems.
Why it matters
CVE-2026-46345 is a high-severity vulnerability in compliance-trestle that allows arbitrary file writes. Defenders should prioritize patching or mitigating this issue, especially in environments where compliance-trestle is used, to prevent potential disruptions and data integrity impacts.
- Potential for arbitrary file writes to attacker-controlled locations
- Possible disruption of compliance-trestle functionality
- Need for verification of affected versions and remediation status
- Potential impact on data integrity and confidentiality
Technical summary
The compliance-trestle tooling platform has a vulnerability that allows writing files outside the intended workspace. This issue is due to improper validation of the `-o/--output` argument in `trestle author jinja`. An attacker can exploit this to write files to attacker-controlled locations, potentially leading to arbitrary file writes and disruptions in compliance-trestle functionality. The vulnerability has a CVSS score of 8.4 and is patched in versions 3.12.3 and 4.0.3. Defenders should prioritize patching or mitigating this vulnerability, especially in environments where compliance-trestle is used.
Defensive priority
Defenders should prioritize patching or mitigating this vulnerability, especially in environments where compliance-trestle is used.
Recommended defensive actions
- Patch compliance-trestle to version 3.12.3 or 4.0.3
- Restrict access to sensitive areas of the workspace
- Monitor for suspicious file writes
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, including its CVSS score and patched versions. The compliance-trestle tooling platform has a vulnerability that allows writing files outside the intended workspace due to improper validation of the `-o/--output` argument in `trestle author jinja`. Defenders should verify affected versions and remediation status, and monitor for suspicious file writes. The vulnerability allows arbitrary file writes to attacker-controlled locations, which could lead to disruptions and a
Sources and references
Verified primary and authoritative sources
-
CVE-2026-46345 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-46345
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-46345 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46345
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/oscal-compass/compliance-trestle/commit/247fcce289f60103f3d8e28d8ec51a6986b94fb6
-
Source reference
Unverified legacy reference
URL: https://github.com/oscal-compass/compliance-trestle/commit/7d107b3ac53caca7bde97a6278b23cd739d94525
-
Source reference
Unverified legacy reference
URL: https://github.com/oscal-compass/compliance-trestle/security/advisories/GHSA-4q5v-7g7x-j79w
-
Source reference
Unverified legacy reference
URL: https://github.com/pypa/advisory-database/tree/main/vulns/compliance-trestle/PYSEC-2026-2423.yaml
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.