Medium severityGHSA Advisory· Published Aug 13, 2026· Updated Aug 14, 2026
CVE-2026-45774
CVE-2026-45774
Description
compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves trestle:// URIs and relative file paths by joining them with trestle_root and calling .resolve(), but performs no boundary check to ensure the resolved path stays within the trestle workspace. An attacker can craft a malicious OSCAL profile YAML with imports[].href containing path traversal sequences to read arbitrary files from the server filesystem. Versions 3.12.3 and 4.0.3 patch the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
compliance-trestlePyPI | >= 4.0.0, < 4.0.3 | 4.0.3 |
compliance-trestlePyPI | < 3.12.2 | 3.12.2 |
Affected products
1- Range: < 3.12.2
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-mj4x-vf5c-5xg8ghsaADVISORY
- github.com/oscal-compass/compliance-trestle/commit/5c65c5926fe7ca908b9c1d281f904e7d97ba8310nvdWEB
- github.com/oscal-compass/compliance-trestle/commit/d00a0c2f702c24f7016009fbd626036f5c46f47bnvdWEB
- github.com/oscal-compass/compliance-trestle/security/advisories/GHSA-mj4x-vf5c-5xg8nvdWEB
- github.com/pypa/advisory-database/tree/main/vulns/compliance-trestle/PYSEC-2026-2426.yamlnvd
News mentions
0No linked articles in our index yet.