<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-05T21:30:22.891078+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-46439</id>
    <title>CVE-2026-46439 — compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)</title>
    <updated>2026-10-05T21:30:22.893969+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> oscal-compass compliance-trestle</p>
<p>compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads into data fields (such as SSP documents or Lookup Tables). The vulnerability does not require attacker control of the template itself. Only attacker-controlled input data rendered into a trusted template is required. This distinction is critical: the template author may only intend to render plain text (e.g., `Title: {{ ssp.metadata.title }}`), but because of the recursive parsing, the data field itself becomes executable. The vulnerability is caused by recursive re-compilation and re-rendering of already-rendered output. Versions 3.12.3 and 4.0.3 patch the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-46439"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-gg2g-p7xc-qqmm</id>
    <title>GHSA-gg2g-p7xc-qqmm — compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)</title>
    <updated>2026-10-05T21:30:22.894037+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: compliance-trestle</p>
<p>A High severity Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads into data fields (such as SSP documents or Lookup Tables).</p>
<p>**The vulnerability does not require attacker control of the template itself. Only attacker-controlled input data rendered into a trusted template is required.**</p>
<p>This distinction is critical: the template author may only intend to render plain text (e.g., `Title: {{ ssp.metadata.title }}`), but because of the recursive parsing, the data field itself becomes executable.</p>
<p>The vulnerability is caused by recursive re-compilation and re-rendering of already-rendered output.</p>
<p>## Details
In `trestle/core/commands/author/jinja.py`, the `render_template` method performs recursive template evaluation to allow nesting within expressions:</p>
<p>```python
    @staticmethod
    def render_template(template: Template, lut: Dict[str, Any], template_folder: pathlib.Path) -&gt; str:
        new_output = template.render(**lut)
        output = ''
        error_countdown = JinjaCmd.max_recursion_depth
        while new_output != output and error_countdown &gt; 0:
            error_countdown = error_countdown - 1
            output = new_output
            random_name = uuid.uuid4()
            dict_loader = DictLoader({str(random_name): new_output})…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-gg2g-p7xc-qqmm"/>
  </entry>
</feed>
