{"apiVersion":"1.0","identifier":"CVE-2026-57171","description":"Compliance-trestle (Trestle) is a Python SDK and command-line tool for managing OSCAL compliance documents. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, the catalog-generate, profile-generate, and ssp-generate author commands write generated Markdown to an attacker-influenced output path without path-traversal validation, allowing arbitrary file write outside the Trestle workspace. These commands join the user-supplied output argument onto the Trestle root and write to the result, but guard it only with an is_directory_name_allowed() task-name-collision check rather than the PathSecurityValidator.validate_local_path() guard used by the jinja command, so an absolute path or one containing traversal sequences escapes the workspace and writes files under an attacker-chosen location as the invoking process owner. The security boundary is crossed when a trusted CI job, shared service, or wrapper derives the output argument from repository-controlled, tenant-controlled, or otherwise untrusted data while expecting output to stay inside the workspace. When --force-overwrite is used, the selected output directory is first recursively deleted, extending the primitive to destruction of an attacker-chosen directory tree and enabling indirect code execution by overwriting files a pipeline later runs. This issue is fixed in versions 3.12.4 and 4.1.0.","publishedAt":"2026-08-26T05:18:11","lastModifiedAt":"2026-08-27T17:18:52","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-57171","cvssScore":7.7,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H","epssProbability":0.00198,"riskScore":0.78,"affectedProduct":"compliance-trestle","affectedVersions":"<3.12.4,>=4.0.0,<=4.0.3","vulnerabilityType":"Library","operatingSystems":[],"links":{"self":"https://www.redsauce.net/api/cves/CVE-2026-57171","webPages":{"es":"https://www.redsauce.net/es/cves/CVE-2026-57171","en":"https://www.redsauce.net/en/cves/CVE-2026-57171","fr":"https://www.redsauce.net/fr/cves/CVE-2026-57171","pt":"https://www.redsauce.net/pt/cves/CVE-2026-57171","de":"https://www.redsauce.net/de/cves/CVE-2026-57171","sk":"https://www.redsauce.net/sk/cves/CVE-2026-57171","el":"https://www.redsauce.net/el/cves/CVE-2026-57171"},"source":"https://nvd.nist.gov/vuln/detail/CVE-2026-57171"}}