CVE-2026-45725
Published:August 13, 2026
Updated:August 31, 2026
compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's remote fetching cache mechanism (HTTPSFetcher and SFTPFetcher) constructs the local cache file path from the URL path component without sanitizing path traversal sequences ("../"). When a remote OSCAL profile references a URL with traversal in its path, the HTTP response body is written to a location outside the intended cache directory, enabling arbitrary file write with attacker-controlled content to the filesystem. Versions 3.12.3 and 4.0.3 patch the issue.
Affected Packages
https://github.com/oscal-compass/compliance-trestle.git (GITHUB):
Affected version(s) >=v4.0.0 <v4.0.3Fix Suggestion:
Update to version v4.0.3https://github.com/oscal-compass/compliance-trestle.git (GITHUB):
Affected version(s) >=v0.0.2 <v3.12.2Fix Suggestion:
Update to version v3.12.2compliance-trestle (PYTHON):
Affected version(s) >=0.0.2 <3.12.2Fix Suggestion:
Update to version 3.12.2compliance-trestle (PYTHON):
Affected version(s) >=4.0.0 <4.0.3Fix Suggestion:
Update to version 4.0.3Related Resources (9)
Do you need more information?
Contact UsCVSS v4
Base Score:
7.1
Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
Vulnerable System Confidentiality
NONE
Vulnerable System Integrity
HIGH
Vulnerable System Availability
NONE
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
6.5
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE
Weakness Type (CWE)
External Control of File Name or Path
EPSS
Base Score:
0.27