CVE-2026-45774: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in oscal-compass compliance-trestle
CVE-2026-45774 is a path traversal vulnerability in the compliance-trestle library of the oscal-compass project. Versions prior to 3.12.3 and 4.0.3 improperly handle pathname resolution for profile imports, allowing crafted OSCAL profile YAML files to access arbitrary files on the server filesystem. This occurs because the library does not verify that resolved paths remain within the intended workspace directory. The issue is patched in versions 3.12.3 and 4.0.3.
AI Analysis
Technical Summary
The compliance-trestle library's profile import mechanism resolves 'trestle://' URIs and relative file paths by joining them with the 'trestle_root' directory and calling '.resolve()'. However, it lacks boundary checks to ensure the resolved path stays within the trestle workspace. An attacker can exploit this by crafting a malicious OSCAL profile YAML with 'imports[].href' containing path traversal sequences, enabling reading of arbitrary files on the server filesystem. This vulnerability is identified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). Versions prior to 3.12.3 and 4.0.3 are affected, with patches released in those versions.
Potential Impact
An attacker can read arbitrary files on the server hosting compliance-trestle by exploiting the path traversal vulnerability in the profile import mechanism. This can lead to unauthorized disclosure of sensitive information stored on the server filesystem. The CVSS 4.0 base score is 6.9 (medium severity), reflecting network attack vector, low attack complexity, no privileges required, user interaction needed, and high impact on confidentiality.
Mitigation Recommendations
Upgrade compliance-trestle to version 3.12.3 or later, or 4.0.3 or later, where this path traversal vulnerability has been patched. No other mitigation is indicated or required according to the available data.
CVE-2026-45774: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in oscal-compass compliance-trestle
Description
CVE-2026-45774 is a path traversal vulnerability in the compliance-trestle library of the oscal-compass project. Versions prior to 3.12.3 and 4.0.3 improperly handle pathname resolution for profile imports, allowing crafted OSCAL profile YAML files to access arbitrary files on the server filesystem. This occurs because the library does not verify that resolved paths remain within the intended workspace directory. The issue is patched in versions 3.12.3 and 4.0.3.
CVSS v4.0
Score 6.9medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The compliance-trestle library's profile import mechanism resolves 'trestle://' URIs and relative file paths by joining them with the 'trestle_root' directory and calling '.resolve()'. However, it lacks boundary checks to ensure the resolved path stays within the trestle workspace. An attacker can exploit this by crafting a malicious OSCAL profile YAML with 'imports[].href' containing path traversal sequences, enabling reading of arbitrary files on the server filesystem. This vulnerability is identified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory). Versions prior to 3.12.3 and 4.0.3 are affected, with patches released in those versions.
Potential Impact
An attacker can read arbitrary files on the server hosting compliance-trestle by exploiting the path traversal vulnerability in the profile import mechanism. This can lead to unauthorized disclosure of sensitive information stored on the server filesystem. The CVSS 4.0 base score is 6.9 (medium severity), reflecting network attack vector, low attack complexity, no privileges required, user interaction needed, and high impact on confidentiality.
Mitigation Recommendations
Upgrade compliance-trestle to version 3.12.3 or later, or 4.0.3 or later, where this path traversal vulnerability has been patched. No other mitigation is indicated or required according to the available data.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-13T07:45:21.251Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7e217cbf8831d539ba0d31
Added to database: 08/13/2026, 19:56:44 UTC
Last enriched: 08/13/2026, 20:12:10 UTC
Last updated: 08/13/2026, 20:12:10 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.