CVE-2026-46439
7.8oscal-compass · compliance-trestle
Compliance-trestle is vulnerable to code injection and improper template engine neutralization, allowing potential arbitrary code execution.
Executive summary
A code injection vulnerability in the compliance-trestle platform poses a high risk of total system compromise if exploited.
Vulnerability
This vulnerability involves improper control of code generation and template engine neutralization (CWE-94 and CWE-1336). It allows an attacker to inject and execute arbitrary code, requiring local access and user interaction to trigger.
Business impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the application process. Given the CVSS score of 7.8, this poses a significant threat to the confidentiality, integrity, and availability of sensitive compliance data managed by the platform.
Remediation
Immediate Action: Update compliance-trestle to version 3.12.2 or 4.0.3 immediately to incorporate the provided security fixes.
Proactive Monitoring: Monitor system logs for suspicious execution patterns or unauthorized file modifications originating from the compliance-trestle process.
Compensating Controls: Ensure the application runs with the principle of least privilege to minimize the impact of potential code execution.
Exploitation status
Public Exploit Available: No (no confirmed weaponized exploit or public PoC identified).
Analyst recommendation
The severity of this vulnerability necessitates immediate patching. Administrators should prioritize upgrading to the specified safe versions to neutralize the risk of arbitrary code execution and protect the integrity of the compliance environment.