# CVE-2026-46345

## Summary

- **CVE ID:** CVE-2026-46345
- **Severity:** HIGH
- **CVSS Score:** 8.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-22, CWE-36, CWE-73
- **Published:** Aug 17, 2026
- **Last Modified:** Aug 17, 2026

## Description

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the `-o/--output` argument in `trestle author jinja` allows writing files outside the intended workspace. The application does not properly validate, `../`,  `..\`, or absolute paths. This allows arbitrary file write to attacker-controlled locations. Versions 3.12.3 and 4.0.3 patch the issue.

## Affected Products

- oscal-compass — compliance-trestle (>= 4.0.0, < 4.0.3)
- oscal-compass — compliance-trestle (< 3.12.2)

## References

- [CNA](https://github.com/oscal-compass/compliance-trestle/security/advisories/GHSA-4q5v-7g7x-j79w)
- [CNA](https://github.com/oscal-compass/compliance-trestle/commit/247fcce289f60103f3d8e28d8ec51a6986b94fb6)
- [CNA](https://github.com/oscal-compass/compliance-trestle/commit/7d107b3ac53caca7bde97a6278b23cd739d94525)
- [CNA](https://github.com/pypa/advisory-database/tree/main/vulns/compliance-trestle/PYSEC-2026-2423.yaml)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._