Skip to main content
EPSS 0.2%top 88%

CVE-2026-57171: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in oscal-compass compliance-trestle

0
High
VulnerabilityCVE-2026-57171cvecve-2026-57171cwe-22
Published: 08/25/2026 (08/25/2026, 23:39:16 UTC)
Source: CVE Database V5
Vendor/Project: oscal-compass
Product: compliance-trestle

Description

Compliance-trestle versions before 3.12.4 and from 4.0.0 through 4.0.3 contain a path traversal vulnerability in certain author commands that write generated Markdown files. This flaw allows an attacker to write files outside the intended workspace by supplying a crafted output path. Using the --force-overwrite option can lead to recursive deletion of attacker-chosen directories, potentially enabling indirect code execution. The issue is fixed in versions 3.12.4 and 4.1.0.

CVSS v3.1

Score 7.7high

Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
High
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Affected software

oscal-compass

compliance-trestle

Affected versions
<3.12.4>=4.0.0 <4.1.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/09/2026, 20:22:41 UTC

Technical Analysis

Compliance-trestle is a Python SDK and CLI tool for managing OSCAL compliance documents. In affected versions, the catalog-generate, profile-generate, and ssp-generate commands improperly validate the user-supplied output path, relying only on a task-name-collision check instead of a full path traversal validation. This allows absolute paths or paths with traversal sequences to escape the workspace boundary and write files arbitrarily on the filesystem with the invoking process's privileges. When the --force-overwrite flag is used, the vulnerability extends to recursive deletion of attacker-controlled directories, which can lead to indirect code execution by overwriting files used later in a pipeline. The vulnerability is addressed in versions 3.12.4 and 4.1.0.

Potential Impact

An attacker who can influence the output path argument can write arbitrary files outside the intended workspace, potentially overwriting critical files. The use of --force-overwrite exacerbates the impact by allowing recursive deletion of directories chosen by the attacker, which can facilitate indirect code execution in CI/CD pipelines or shared services. This compromises the integrity and availability of the system where compliance-trestle runs, especially in automated or multi-tenant environments.

Mitigation Recommendations

Upgrade compliance-trestle to version 3.12.4 or later, or 4.1.0 or later, where the vulnerability is fixed. Until upgraded, avoid using untrusted input for the output path argument in the affected commands and avoid using the --force-overwrite option with untrusted data. Patch status is not explicitly stated in the vendor advisory, but the fix is included in the specified versions.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-06-24T01:47:55.285Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6a8e2ad4acd9273b49dc8688

Added to database: 08/25/2026, 23:52:52 UTC

Last enriched: 09/09/2026, 20:22:41 UTC

Last updated: 10/09/2026, 06:48:18 UTC

Views: 70

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses