These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-57171 is a high-severity vulnerability in the Compliance-trestle (Trestle) Python SDK and command-line tool. It allows for arbitrary file writes outside the Trestle workspace due to insufficient path-traversal validation in certain commands. This issue is fixed in versions 3.12.4 and 4.1.0. The vulnerability is caused by the catalog-generate, profile-generate, and ssp-generate author commands wri [truncated]
CVE-2026-57170 is a high-severity vulnerability in the Compliance-trestle (Trestle) Python SDK and command-line tool, which allows server-side template injection that can lead to arbitrary code execution. The vulnerability affects versions prior to 3.12.4 and 4.0.0 through 4.0.3. Trestle's custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown file a [truncated]
Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the URLSecurityValidator that guards trestle's remote-fetch paths against server-side request forgery can be bypassed to reach loopback, link-local, cloud-metadata, and internal network endpoints it was designed to block. The blocklist does not canonicalize IPv4-m [truncated]
CVE-2026-54757 is a server-side template injection vulnerability in Compliance-trestle (Trestle) that can lead to remote code execution. The vulnerability affects versions before 3.12.4 and versions 4.0.0 through 4.0.3. An attacker who controls content that Trestle renders can inject a Jinja2 expression to execute arbitrary operating system commands. This issue is fixed in versions 3.12.4 and 4.1.0.
CVE-2026-46345 is a high-severity vulnerability in the compliance-trestle tooling platform used for managing compliance as code. An attacker can exploit this issue to write files outside the intended workspace, potentially leading to arbitrary file writes. The vulnerability is due to improper validation of the `-o/--output` argument in `trestle author jinja`, allowing an attacker to write files to attacke [truncated]
CVE-2026-46439 is a Server-Side Template Injection (SSTI) vulnerability in compliance-trestle, a tool for managing compliance as code. The vulnerability exists in the `trestle author jinja` command and allows for arbitrary command execution with the privileges of the running process by injecting malicious payloads into data fields. This issue was patched in versions 3.12.3 and 4.0.3.
CVE-2026-46380 is a Server-Side Request Forgery (SSRF) vulnerability in compliance-trestle, a tool for managing compliance as code. An attacker can exploit this vulnerability by providing a specially crafted URL to the HTTPSFetcher._do_fetch() method, which can lead to unauthorized access to internal services or cloud metadata endpoints. The vulnerability has been fixed in versions 3.12.2 and 4.0.3 of com [truncated]
CVE-2026-45774 is a vulnerability in the compliance-trestle tooling platform that allows an attacker to read arbitrary files from the server filesystem by crafting a malicious OSCAL profile YAML with path traversal sequences. The vulnerability is caused by the compliance-trestle library's profile import mechanism resolving `trestle://` URIs and relative file paths without boundary checks, allowing path tr [truncated]
CVE-2026-45725 is a high-severity vulnerability in the compliance-trestle tooling platform that allows for arbitrary file writes with attacker-controlled content. The vulnerability exists in the remote fetching cache mechanism, which fails to sanitize path traversal sequences. This issue was patched in versions 3.12.3 and 4.0.3. Defenders responsible for managing compliance as code using the compliance-tr [truncated]