PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-46439 oscal-compass CVE debrief

CVE-2026-46439 is a Server-Side Template Injection (SSTI) vulnerability in compliance-trestle, a tool for managing compliance as code. The vulnerability exists in the `trestle author jinja` command and allows for arbitrary command execution with the privileges of the running process by injecting malicious payloads into data fields. This issue was patched in versions 3.12.3 and 4.0.3.

Vendor
oscal-compass
Product
compliance-trestle
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-14
Original CVE updated
2026-09-18
Advisory published
2026-08-14
Advisory updated
2026-09-18

Who should care

Defenders managing compliance-trestle deployments, especially those rendering untrusted input in templates, should assess exposure and apply patches or mitigations as available. Defenders should prioritize verifying exposure in compliance-trestle deployments, especially where untrusted input is rendered in templates, and apply patches or mitigations as available. This includes operators, platform administrators, vulnerability management teams, and security

Why it matters

CVE-2026-46439 is a Server-Side Template Injection (SSTI) vulnerability in compliance-trestle that allows for arbitrary command execution. Defenders should prioritize verifying exposure and applying patches or mitigations.

  • Potential for arbitrary command execution with privileges of the running process
  • Need for verification of exposure in compliance-trestle deployments
  • Priority for applying patches or mitigations
  • Importance of monitoring for suspicious activity in compliance-trestle environments

Technical summary

The `trestle author jinja` command in compliance-trestle recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads into data fields. This vulnerability is caused by recursive re-compilation and re-rendering of already-rendered output. Defenders should prioritize verifying exposure in compliance-trestle deployments, especially where untrusted input is rendered in templates, and apply patches or mitigations as available. The vulnerability does not require attacker control of the template itself.

Defensive priority

Defenders should prioritize verifying exposure in compliance-trestle deployments, especially where untrusted input is rendered in templates, and apply patches or mitigations as available.

Recommended defensive actions

  • Verify compliance-trestle deployments for exposure to untrusted input in templates
  • Apply patches or mitigations as available
  • Monitor for suspicious activity in compliance-trestle environments
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and patched versions. However, specific details about exploitation or victim impact are not provided. Defenders should verify exposure in compliance-trestle deployments, especially where untrusted input is rendered in templates, and apply patches or mitigations as available. The vulnerability exists in the `trestle author jinja` command and allows for arbitrary command execution with privileges of the running process by injecting malicious payloads 3

Sources and references

Verified primary and authoritative sources

  • CVE-2026-46439 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-46439

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-46439 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-46439

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.