No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 26 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 26 Aug 2026 01:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oscal-compass
Oscal-compass compliance-trestle |
|
| Vendors & Products |
Oscal-compass
Oscal-compass compliance-trestle |
Tue, 25 Aug 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, Trestle is vulnerable to server-side template injection that can lead to remote code execution. This occurs because the MDCleanInclude and MDSectionInclude Jinja2 tags re-parse untrusted Markdown content as template source code using a non-sandboxed jinja2.Environment. An attacker who controls content that Trestle renders, such as a crafted workspace Markdown file, a third-party SSP document, or a YAML lookup-table value, can inject a Jinja2 expression that traverses Python object internals to execute arbitrary operating system commands in the context of the Trestle process. This issue is fixed in versions 3.12.4 and 4.1.0. | |
| Title | Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-26T12:21:23.031Z
Reserved: 2026-06-15T23:12:41.965Z
Link: CVE-2026-54757
Updated: 2026-08-26T12:20:50.152Z
Status : Received
Published: 2026-08-25T23:17:19.277
Modified: 2026-08-26T13:19:16.497
Link: CVE-2026-54757
No data.
OpenCVE Enrichment
Updated: 2026-08-26T01:15:04Z