VYPR

Compliance Trestle

by Oscal Compass

Source repositories

CVEs (1)

  • CVE-2026-45725higMay 27, 2026
    risk 0.38cvss epss

    ## Summary The compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (`../`). When a remote OSCAL profile references a URL with…