<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T23:12:35.292285+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-354513</id>
    <title>EUVD-2026-354513</title>
    <updated>2026-10-05T23:12:35.294746+00:00</updated>
    <content>EUVD-2026-354513</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-354513"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-45725</id>
    <title>fkie_cve-2026-45725</title>
    <updated>2026-10-05T23:12:35.294787+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (`../`). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location outside the intended cache directory, enabling arbitrary file write with attacker-controlled content to the filesystem. Versions 3.12.3 and 4.0.3 patch the issue.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-45725"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-g3vg-vx23-3858</id>
    <title>GHSA-g3vg-vx23-3858 — compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal</title>
    <updated>2026-10-05T23:12:35.294826+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: compliance-trestle</p>
<p>## Summary</p>
<p>The compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (`../`). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location **outside the intended cache directory**, enabling **arbitrary file write with attacker-controlled content** to the filesystem.</p>
<p>**Attack chain:** Malicious OSCAL profile → HTTPS fetch → cache path traversal → arbitrary file write → RCE (via cron, SSH keys, etc.)</p>
<p>## Affected Component</p>
<p>**Repository:** https://github.com/IBM/compliance-trestle
**File:** `trestle/core/remote/cache.py` (lines 259-266 for HTTPSFetcher, lines 328-333 for SFTPFetcher)
**Version:** v4.0.2 (latest as of 2026-04-30)
## Vulnerable Code</p>
<p>### cache.py:259-266 — HTTPSFetcher cache path construction</p>
<p>```python
class HTTPSFetcher(FetcherBase):
    def __init__(self, trestle_root: pathlib.Path, uri: str) -&gt; None:
        # ...
        u = parse.urlparse(self._uri)
        # ...
        if u.hostname is None:
            raise TrestleError(f'Cache request for {self._uri} requires hostname')
        https_cached_dir = self._trestle_cache_path / u.hostname
        # ❌ path_parent preserves ../ sequences from URL
        path_parent = pathlib.Path(u.path[re.search('[^/\\\\]', u.path).span()[0] :]).parent
        https_cached_dir = https_cached_dir / path_parent…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-g3vg-vx23-3858"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-2424</id>
    <title>PYSEC-2026-2424 — compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal</title>
    <updated>2026-10-05T23:12:35.294905+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: compliance-trestle</p>
<p>## Summary</p>
<p>The compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences (`../`). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location **outside the intended cache directory**, enabling **arbitrary file write with attacker-controlled content** to the filesystem.</p>
<p>**Attack chain:** Malicious OSCAL profile → HTTPS fetch → cache path traversal → arbitrary file write → RCE (via cron, SSH keys, etc.)</p>
<p>## Affected Component</p>
<p>**Repository:** https://github.com/IBM/compliance-trestle
**File:** `trestle/core/remote/cache.py` (lines 259-266 for HTTPSFetcher, lines 328-333 for SFTPFetcher)
**Version:** v4.0.2 (latest as of 2026-04-30)
## Vulnerable Code</p>
<p>### cache.py:259-266 — HTTPSFetcher cache path construction</p>
<p>```python
class HTTPSFetcher(FetcherBase):
    def __init__(self, trestle_root: pathlib.Path, uri: str) -&gt; None:
        # ...
        u = parse.urlparse(self._uri)
        # ...
        if u.hostname is None:
            raise TrestleError(f'Cache request for {self._uri} requires hostname')
        https_cached_dir = self._trestle_cache_path / u.hostname
        # ❌ path_parent preserves ../ sequences from URL
        path_parent = pathlib.Path(u.path[re.search('[^/\\\\]', u.path).span()[0] :]).parent
        https_cached_dir = https_cached_dir / path_parent…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-2424"/>
  </entry>
</feed>
