<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Mon, 05 Oct 2026 17:23:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-354496</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-354496</link>
      <description>EUVD-2026-354496</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-354496</guid>
    </item>
    <item>
      <title>fkie_cve-2026-46345</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-46345</link>
      <description>&lt;p&gt;compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly validate, `../`,  `..\`, or absolute paths. This allows arbitrary file write to attacker-controlled locations. Versions 3.12.3 and 4.0.3 patch the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly validate, `../`,  `..\`, or absolute paths. This allows arbitrary file write to attacker-controlled locations. Versions 3.12.3 and 4.0.3 patch the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-46345</guid>
    </item>
    <item>
      <title>GHSA-4q5v-7g7x-j79w — compliance-trestle - jinja has an Arbitrary File Write via Path Traversal</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4q5v-7g7x-j79w</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: compliance-trestle&lt;/p&gt;
&lt;p&gt;**Relevant Products/Components:**&lt;/p&gt;
&lt;p&gt;* `trestle/core/commands/author/jinja.py`
* `trestle author jinja`&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Detailed Description:&lt;/p&gt;
&lt;p&gt;The `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace.&lt;/p&gt;
&lt;p&gt;The application does not properly validate:&lt;/p&gt;
&lt;p&gt;* `../`
* `..\`
* absolute paths&lt;/p&gt;
&lt;p&gt;This allows arbitrary file write to attacker-controlled locations.&lt;/p&gt;
&lt;p&gt;Vulnerable code:&lt;/p&gt;
&lt;p&gt;```python
output_file = trestle_root / r_output_file
```&lt;/p&gt;
&lt;p&gt;An attacker can overwrite files such as:&lt;/p&gt;
&lt;p&gt;* `.github/workflows/*.yml`
* `.git/hooks/*`
* user writable config files&lt;/p&gt;
&lt;p&gt;This can lead to CI/CD compromise or local code execution.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Steps To Reproduce:&lt;/p&gt;
&lt;p&gt;1. Clone the repository:&lt;/p&gt;
&lt;p&gt;```bash
git clone https://github.com/oscal-compass/compliance-trestle.git
cd compliance-trestle
```&lt;/p&gt;
&lt;p&gt;2. Create template:&lt;/p&gt;
&lt;p&gt;```bash
echo &amp;#34;hello&amp;#34; &amp;gt; template.j2
```&lt;/p&gt;
&lt;p&gt;3. Run:&lt;/p&gt;
&lt;p&gt;```powershell
trestle author jinja -i template.j2 -o &amp;#34;subdir\..\..\..\..\..\poc.txt&amp;#34;
```&lt;/p&gt;
&lt;p&gt;4. Observe:&lt;/p&gt;
&lt;p&gt;```powershell
dir E:\poc.txt
```&lt;/p&gt;
&lt;p&gt;The file is written outside the repository workspace.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Browsers Verified In:&lt;/p&gt;
&lt;p&gt;Not browser related.&lt;/p&gt;
&lt;p&gt;Tested on:&lt;/p&gt;
&lt;p&gt;* Windows 11
* Python 3.13&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Supporting Material/References:&lt;/p&gt;
&lt;p&gt;Affected file:&lt;/p&gt;
&lt;p&gt;```text
trestle/core/commands/author/jinja.py
```&lt;/p&gt;
&lt;p&gt;Successfully verified:&lt;/p&gt;
&lt;p&gt;* directory traversal using `../`
* Windows traversal using `..\`
* arbitrary file write outside workspace&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Access Vector Required for Exploitation:&lt;/p&gt;
&lt;p&gt;Local&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Vulnerability Exists in Default Configurat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: compliance-trestle&lt;/p&gt;
&lt;p&gt;**Relevant Products/Components:**&lt;/p&gt;
&lt;p&gt;* `trestle/core/commands/author/jinja.py`
* `trestle author jinja`&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Detailed Description:&lt;/p&gt;
&lt;p&gt;The `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace.&lt;/p&gt;
&lt;p&gt;The application does not properly validate:&lt;/p&gt;
&lt;p&gt;* `../`
* `..\`
* absolute paths&lt;/p&gt;
&lt;p&gt;This allows arbitrary file write to attacker-controlled locations.&lt;/p&gt;
&lt;p&gt;Vulnerable code:&lt;/p&gt;
&lt;p&gt;```python
output_file = trestle_root / r_output_file
```&lt;/p&gt;
&lt;p&gt;An attacker can overwrite files such as:&lt;/p&gt;
&lt;p&gt;* `.github/workflows/*.yml`
* `.git/hooks/*`
* user writable config files&lt;/p&gt;
&lt;p&gt;This can lead to CI/CD compromise or local code execution.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Steps To Reproduce:&lt;/p&gt;
&lt;p&gt;1. Clone the repository:&lt;/p&gt;
&lt;p&gt;```bash
git clone https://github.com/oscal-compass/compliance-trestle.git
cd compliance-trestle
```&lt;/p&gt;
&lt;p&gt;2. Create template:&lt;/p&gt;
&lt;p&gt;```bash
echo &amp;#34;hello&amp;#34; &amp;gt; template.j2
```&lt;/p&gt;
&lt;p&gt;3. Run:&lt;/p&gt;
&lt;p&gt;```powershell
trestle author jinja -i template.j2 -o &amp;#34;subdir\..\..\..\..\..\poc.txt&amp;#34;
```&lt;/p&gt;
&lt;p&gt;4. Observe:&lt;/p&gt;
&lt;p&gt;```powershell
dir E:\poc.txt
```&lt;/p&gt;
&lt;p&gt;The file is written outside the repository workspace.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Browsers Verified In:&lt;/p&gt;
&lt;p&gt;Not browser related.&lt;/p&gt;
&lt;p&gt;Tested on:&lt;/p&gt;
&lt;p&gt;* Windows 11
* Python 3.13&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Supporting Material/References:&lt;/p&gt;
&lt;p&gt;Affected file:&lt;/p&gt;
&lt;p&gt;```text
trestle/core/commands/author/jinja.py
```&lt;/p&gt;
&lt;p&gt;Successfully verified:&lt;/p&gt;
&lt;p&gt;* directory traversal using `../`
* Windows traversal using `..\`
* arbitrary file write outside workspace&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Access Vector Required for Exploitation:&lt;/p&gt;
&lt;p&gt;Local&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Vulnerability Exists in Default Configurat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4q5v-7g7x-j79w</guid>
    </item>
    <item>
      <title>PYSEC-2026-2423 — compliance-trestle - jinja has an Arbitrary File Write via Path Traversal</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-2423</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: compliance-trestle&lt;/p&gt;
&lt;p&gt;**Relevant Products/Components:**&lt;/p&gt;
&lt;p&gt;* `trestle/core/commands/author/jinja.py`
* `trestle author jinja`&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Detailed Description:&lt;/p&gt;
&lt;p&gt;The `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace.&lt;/p&gt;
&lt;p&gt;The application does not properly validate:&lt;/p&gt;
&lt;p&gt;* `../`
* `..\`
* absolute paths&lt;/p&gt;
&lt;p&gt;This allows arbitrary file write to attacker-controlled locations.&lt;/p&gt;
&lt;p&gt;Vulnerable code:&lt;/p&gt;
&lt;p&gt;```python
output_file = trestle_root / r_output_file
```&lt;/p&gt;
&lt;p&gt;An attacker can overwrite files such as:&lt;/p&gt;
&lt;p&gt;* `.github/workflows/*.yml`
* `.git/hooks/*`
* user writable config files&lt;/p&gt;
&lt;p&gt;This can lead to CI/CD compromise or local code execution.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Steps To Reproduce:&lt;/p&gt;
&lt;p&gt;1. Clone the repository:&lt;/p&gt;
&lt;p&gt;```bash
git clone https://github.com/oscal-compass/compliance-trestle.git
cd compliance-trestle
```&lt;/p&gt;
&lt;p&gt;2. Create template:&lt;/p&gt;
&lt;p&gt;```bash
echo &amp;#34;hello&amp;#34; &amp;gt; template.j2
```&lt;/p&gt;
&lt;p&gt;3. Run:&lt;/p&gt;
&lt;p&gt;```powershell
trestle author jinja -i template.j2 -o &amp;#34;subdir\..\..\..\..\..\poc.txt&amp;#34;
```&lt;/p&gt;
&lt;p&gt;4. Observe:&lt;/p&gt;
&lt;p&gt;```powershell
dir E:\poc.txt
```&lt;/p&gt;
&lt;p&gt;The file is written outside the repository workspace.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Browsers Verified In:&lt;/p&gt;
&lt;p&gt;Not browser related.&lt;/p&gt;
&lt;p&gt;Tested on:&lt;/p&gt;
&lt;p&gt;* Windows 11
* Python 3.13&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Supporting Material/References:&lt;/p&gt;
&lt;p&gt;Affected file:&lt;/p&gt;
&lt;p&gt;```text
trestle/core/commands/author/jinja.py
```&lt;/p&gt;
&lt;p&gt;Successfully verified:&lt;/p&gt;
&lt;p&gt;* directory traversal using `../`
* Windows traversal using `..\`
* arbitrary file write outside workspace&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Access Vector Required for Exploitation:&lt;/p&gt;
&lt;p&gt;Local&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Vulnerability Exists in Default Configurat…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: compliance-trestle&lt;/p&gt;
&lt;p&gt;**Relevant Products/Components:**&lt;/p&gt;
&lt;p&gt;* `trestle/core/commands/author/jinja.py`
* `trestle author jinja`&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Detailed Description:&lt;/p&gt;
&lt;p&gt;The `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace.&lt;/p&gt;
&lt;p&gt;The application does not properly validate:&lt;/p&gt;
&lt;p&gt;* `../`
* `..\`
* absolute paths&lt;/p&gt;
&lt;p&gt;This allows arbitrary file write to attacker-controlled locations.&lt;/p&gt;
&lt;p&gt;Vulnerable code:&lt;/p&gt;
&lt;p&gt;```python
output_file = trestle_root / r_output_file
```&lt;/p&gt;
&lt;p&gt;An attacker can overwrite files such as:&lt;/p&gt;
&lt;p&gt;* `.github/workflows/*.yml`
* `.git/hooks/*`
* user writable config files&lt;/p&gt;
&lt;p&gt;This can lead to CI/CD compromise or local code execution.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Steps To Reproduce:&lt;/p&gt;
&lt;p&gt;1. Clone the repository:&lt;/p&gt;
&lt;p&gt;```bash
git clone https://github.com/oscal-compass/compliance-trestle.git
cd compliance-trestle
```&lt;/p&gt;
&lt;p&gt;2. Create template:&lt;/p&gt;
&lt;p&gt;```bash
echo &amp;#34;hello&amp;#34; &amp;gt; template.j2
```&lt;/p&gt;
&lt;p&gt;3. Run:&lt;/p&gt;
&lt;p&gt;```powershell
trestle author jinja -i template.j2 -o &amp;#34;subdir\..\..\..\..\..\poc.txt&amp;#34;
```&lt;/p&gt;
&lt;p&gt;4. Observe:&lt;/p&gt;
&lt;p&gt;```powershell
dir E:\poc.txt
```&lt;/p&gt;
&lt;p&gt;The file is written outside the repository workspace.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Browsers Verified In:&lt;/p&gt;
&lt;p&gt;Not browser related.&lt;/p&gt;
&lt;p&gt;Tested on:&lt;/p&gt;
&lt;p&gt;* Windows 11
* Python 3.13&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Supporting Material/References:&lt;/p&gt;
&lt;p&gt;Affected file:&lt;/p&gt;
&lt;p&gt;```text
trestle/core/commands/author/jinja.py
```&lt;/p&gt;
&lt;p&gt;Successfully verified:&lt;/p&gt;
&lt;p&gt;* directory traversal using `../`
* Windows traversal using `..\`
* arbitrary file write outside workspace&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Access Vector Required for Exploitation:&lt;/p&gt;
&lt;p&gt;Local&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Vulnerability Exists in Default Configurat…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-2423</guid>
    </item>
  </channel>
</rss>
