compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
Modified: 8/27/2026
package
pkg:pypi/compliance-trestle
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
Modified: 8/27/2026
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal
Modified: 7/13/2026
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
Modified: 7/13/2026
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
Modified: 8/19/2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
Modified: 9/10/2026
compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal
Modified: 7/13/2026
Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)
Modified: 9/24/2026
Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)
Modified: 9/24/2026
compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
Modified: 7/13/2026
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
Modified: 7/13/2026
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal
Modified: 7/13/2026
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
Modified: 7/13/2026
compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal
Modified: 7/13/2026
compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
Modified: 7/13/2026
compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0
Modified: 8/19/2026
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
Modified: 9/10/2026