SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-57171

HIGH · CVSS 7.7 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Versions prior to 3.12.4 and 4.0.0 through 4.0.3 of the Compliance-trestle SDK are vulnerable to arbitrary file write due to insufficient path traversal validation in the catalog-generate, profile-generate, and ssp-generate commands. This flaw allows attackers to manipulate output paths, potentially leading to unauthorized file creation or deletion outside the intended workspace, which can facilitate indirect code execution. Organizations utilizing this SDK, especially those integrating it into CI/CD pipelines or handling untrusted data, should prioritize upgrading to versions 3.12.4 or 4.1.0 to mitigate these risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-57171
Severity
HIGH
CVSS
7.7
EPSS
0.20%

Original NVD Description

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an attacker-influenced output path without path-traversal validation, allowing arbitrary file write outside the Trestle workspace. These commands join the user-supplied output argument onto the Trestle root and write to the result, but guard it only with an is_directory_name_allowed() task-name-collision check rather than the PathSecurityValidator.validate_local_path() guard used by the jinja command, so an absolute path or one containing traversal sequences escapes the workspace and writes files under an attacker-chosen location as the invoking process owner. The security boundary is crossed when a trusted CI job, shared service, or wrapper derives the output argument from repository-controlled, tenant-controlled, or otherwise untrusted data while expecting output to stay inside the workspace. When --force-overwrite is used, the selected output directory is first recursively deleted, extending the primitive to destruction of an attacker-chosen directory tree and enabling indirect code execution by overwriting files a pipeline later runs. This issue is fixed in versions 3.12.4 and 4.1.0.