CVE-2026-57171: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in oscal-compass compliance-trestle
Description
Compliance-trestle versions before 3.12.4 and from 4.0.0 through 4.0.3 contain a path traversal vulnerability in certain author commands that write generated Markdown files. This flaw allows an attacker to write files outside the intended workspace by supplying a crafted output path. Using the --force-overwrite option can lead to recursive deletion of attacker-chosen directories, potentially enabling indirect code execution. The issue is fixed in versions 3.12.4 and 4.1.0.
CVSS v3.1
Score 7.7high
Affected software
oscal-compass
compliance-trestle
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Compliance-trestle is a Python SDK and CLI tool for managing OSCAL compliance documents. In affected versions, the catalog-generate, profile-generate, and ssp-generate commands improperly validate the user-supplied output path, relying only on a task-name-collision check instead of a full path traversal validation. This allows absolute paths or paths with traversal sequences to escape the workspace boundary and write files arbitrarily on the filesystem with the invoking process's privileges. When the --force-overwrite flag is used, the vulnerability extends to recursive deletion of attacker-controlled directories, which can lead to indirect code execution by overwriting files used later in a pipeline. The vulnerability is addressed in versions 3.12.4 and 4.1.0.
Potential Impact
An attacker who can influence the output path argument can write arbitrary files outside the intended workspace, potentially overwriting critical files. The use of --force-overwrite exacerbates the impact by allowing recursive deletion of directories chosen by the attacker, which can facilitate indirect code execution in CI/CD pipelines or shared services. This compromises the integrity and availability of the system where compliance-trestle runs, especially in automated or multi-tenant environments.
Mitigation Recommendations
Upgrade compliance-trestle to version 3.12.4 or later, or 4.1.0 or later, where the vulnerability is fixed. Until upgraded, avoid using untrusted input for the output path argument in the affected commands and avoid using the --force-overwrite option with untrusted data. Patch status is not explicitly stated in the vendor advisory, but the fix is included in the specified versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-06-24T01:47:55.285Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a8e2ad4acd9273b49dc8688
Added to database: 08/25/2026, 23:52:52 UTC
Last enriched: 09/09/2026, 20:22:41 UTC
Last updated: 10/09/2026, 06:48:18 UTC
Views: 70
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.