Threat Advisory

Trestle Flaw Allows Absolute Paths and Non-Leading .. Segments

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Compliance-Trestle is affected by two high-severity vulnerabilities involving server-side template injection and arbitrary file writes through path traversal. Both vulnerabilities are incomplete fixes for previously reported issues and can be exploited when attacker-controlled OSCAL data or output-path values are processed by automated Trestle workflows.

CVE-2026-57170 (CVSS v3 7.8 – High): An incomplete fix for a previous SSTI vulnerability allows attacker-controlled OSCAL content written into Markdown files to be re-parsed as Jinja2 templates by the mdsection_include and md_clean_include tags. Because the Jinja environment is not sandboxed, crafted template expressions can result in arbitrary code execution with the privileges of the Trestle process, including a CI runner.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Compliance-Trestle is affected by two high-severity vulnerabilities involving server-side template injection and arbitrary file writes through path traversal. Both vulnerabilities are incomplete fixes for previously reported issues and can be exploited when attacker-controlled OSCAL data or output-path values are processed by automated Trestle workflows.

CVE-2026-57170 (CVSS v3 7.8 – High): An incomplete fix for a previous SSTI vulnerability allows attacker-controlled OSCAL content written into Markdown files to be re-parsed as Jinja2 templates by the mdsection_include and md_clean_include tags. Because the Jinja environment is not sandboxed, crafted template expressions can result in arbitrary code execution with the privileges of the Trestle process, including a CI runner.[emaillocker id="1283"]

CVE-2026-57171 (CVSS v3 8.4 – High): An incomplete path-traversal fix allows attacker-controlled --output values in catalog-generate, profile-generate, and ssp-generate commands to escape the Trestle workspace and write files to arbitrary locations permitted by the process. With --force-overwrite, an attacker-selected directory can also be recursively deleted, creating integrity and availability risks.

RECOMMENDATION:

We recommend you to upgrade trestle to the 4.1.0 version.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu