CVE-2026-46439Disclosure

LOWCVSS 7.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja` command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary command execution with privileges of the running process by injecting malicious payloads into data fields (such as SSP documents or Lookup Tables). The vulnerability does not require attacker control of the template itself. Only attacker-controlled input data rendered into a trusted template is required. This distinction is critical: the template author may only intend to render plain text (e.g., `Title: {{ ssp.metadata.title }}`), but because of the recursive parsing, the data field itself becomes executable. The vulnerability is caused by recursive re-compilation and re-rendering of already-rendered output. Versions 3.12.3 and 4.0.3 patch the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-1336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-08-14); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-08-14: 2Mentions · 2026-09-25: 1Technical Details · 2026-08-14: 208-1409-25
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-46439 compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerabilit… https://www.cve.org/CVERecord?id=CVE-2026-46439

    Post summary

    The post notes that CVE‑2026‑46439 is a Server‑Side Template Injection flaw affecting compliance‑trestle versions prior to 3.12.2 and 4.0.3, but does not provide exploits, patches, or evidence of active exploitation.

    000011.0K
    57.9K followersView on X
  • DailyCVE@dailycve

    🔴 Trestle, Incomplete Fix Jinja2 SSTI/RCE Include Re-Parse, #CVE-2026-46439 (Critical) -DC-Sep2026-2566 https://dailycve.com/trestle-incomplete-fix-jinja2-ssti-rce-include-re-parse-cve-2026-46439-critical-dc-sep2026-2566/

    0000038
    238 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-46439 compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (SSTI) vulnerabilit… https://www.cve.org/CVERecord?id=CVE-2026-46439 ----- Traducción: CVE-2026-46439 com… https://infoflow.cloud`

    Post summary

    The tweet announces a new CVE (CVE‑2026‑46439) for compliance‑trestle, providing the vulnerability type (SSTI) and affected versions, but offers no PoC, exploit code, active exploitation status, or patch information.

    0000033
    98 followersView on X

Explore more