{"apiVersion":"1.0","identifier":"CVE-2026-57170","description":"Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions prior to 3.12.4 and 4.0.0 through 4.0.3, the custom Jinja2 include tags mdsection_include and md_clean_include re-parse the content of an included Markdown file as Jinja2 template code in a non-sandboxed environment, allowing server-side template injection that can lead to arbitrary code execution. The MDSectionInclude and MDCleanInclude tags in Trestle/core/jinja/tags.py pass included file content to Parser(self.environment, ...).parse(), splicing it into the host template-s compilation, and the environment is a plain jinja2.Environment rather than a SandboxedEnvironment, so any expressions in the file are evaluated with full access to the usual SSTI gadget chain. Because Trestle-s Markdown writers emit OSCAL prose and component-description fields verbatim, applying delimiter neutralization only to parameter tables, attacker-controlled OSCAL data such as a control statement, part prose, or component description containing Jinja2 syntax flows into an included Markdown file and is executed when the include tag re-parses it. This issue is fixed in version 4.1.0.","publishedAt":"2026-08-26T05:18:11","lastModifiedAt":null,"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57170","cvssScore":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","epssProbability":0.00204,"riskScore":0.79,"affectedProduct":"compliance-trestle","affectedVersions":"<3.12.4,>=4.0.0,<=4.0.3","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-57170","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-57170","en":"https://www.redsauce.net/en/cves/CVE-2026-57170","fr":"https://www.redsauce.net/fr/cves/CVE-2026-57170","pt":"https://www.redsauce.net/pt/cves/CVE-2026-57170","de":"https://www.redsauce.net/de/cves/CVE-2026-57170","sk":"https://www.redsauce.net/sk/cves/CVE-2026-57170","el":"https://www.redsauce.net/el/cves/CVE-2026-57170"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-57170"}}