CVE-2026-45774 PUBLISHED

compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal

Assigner: GitHub_M
Reserved: 13.05.2026 Published: 13.08.2026 Updated: 13.08.2026

compliance-trestle is a tooling platform for managing compliance as code. Prior to versiions 3.12.2 and 4.0.3, the compliance-trestle library's profile import mechanism resolves trestle:// URIs and relative file paths by joining them with trestle_root and calling .resolve(), but performs no boundary check to ensure the resolved path stays within the trestle workspace. An attacker can craft a malicious OSCAL profile YAML with imports[].href containing path traversal sequences to read arbitrary files from the server filesystem. Versions 3.12.3 and 4.0.3 patch the issue.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor oscal-compass
Product compliance-trestle
Versions
  • Version < 3.12.2 is affected
  • Version >= 4.0.0, < 4.0.3 is affected

References

Problem Types

  • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE