SCA: security update for compliance-trestle (GHSA-gg2g-p7xc-qqmm)

high Tenable Cloud Security Plugin ID 442428

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and
4.0.3 have a Server-Side Template Injection (SSTI) vulnerability exists in the `trestle author jinja`
command. The command recursively evaluates rendered templates, allowing an attacker to achieve arbitrary
command execution with privileges of the running process by injecting malicious payloads into data fields
(such as SSP documents or Lookup Tables). The vulnerability does not require attacker control of the
template itself. Only attacker-controlled input data rendered into a trusted template is required. This
distinction is critical: the template author may only intend to render plain text (e.g., `Title: {{
ssp.metadata.title }}`), but because of the recursive parsing, the data field itself becomes executable.
The vulnerability is caused by recursive re-compilation and re-rendering of already-rendered output.
Versions 3.12.3 and 4.0.3 patch the issue. (CVE-2026-46439)

Solution

Update the compliance-trestle library and its related packages to version 3.12.2 or later.

See Also

https://github.com/advisories/GHSA-gg2g-p7xc-qqmm

Plugin Details

Severity: High

ID: 442428

Version: Revision 1.4

Type: Local

Family: SCA Checks

Published: 5/28/2026

Updated: 8/18/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.93

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-46439

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 5/28/2026

Vulnerability Publication Date: 5/28/2026

Reference Information

CVE: CVE-2026-46439