[CVE-2026-57170] Compliance-trestle (Trestle) is a Python SDK and command-lin

CVE-2026-57170 | CVSS: 7.8 | 严重级别: HIGH

Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown file as Jinja2 template code in a non-sandboxed environment, allowing server-side template injection that can lead to arbitrary code execution. The MDSectionInclude and MDCleanInclude tags in Trestle/core/jinja/tags.py pass included file content to Parser(self.environment, …).parse(), splicing it into the host template's

参考链接:
https://github.com/oscal-compass/compliance-trestle/commit/0f82d19bd42f9cc0f1b3a
https://github.com/oscal-compass/compliance-trestle/commit/5335ff873a2a68eb7de43
https://github.com/oscal-compass/compliance-trestle/security/advisories/GHSA-mr9

📌 数据来源: NVD 官方

⚠️ 合规声明: 本文内容仅用于网络安全合规学习、科研与授权测试用途。严禁用于任何未授权行为,违者自行承担全部法律责任。
滚动至顶部