VYPR

trestle-auth

by TrestleAdmin

Source repositories

CVEs (2)

  • CVE-2026-46380May 28, 2026
    risk 0.00cvss epss

    A source code audit led to the discovery of three significant security vulnerabilities in the trestle/core/remote/cache.py module. **Finding 1 (Critical): SSRF (CWE-918)** The HTTPSFetcher._do_fetch() method passes a user-supplied URL directly to requests.get() without…

  • CVE-2021-29435Apr 13, 2021
    risk 0.00cvss epss 0.00

    trestle-auth is an authentication plugin for the Trestle admin framework. A vulnerability in trestle-auth versions 0.4.0 and 0.4.1 allows an attacker to create a form that will bypass Rails' built-in CSRF protection when submitted by a victim with a trestle-auth admin session.…