Impact
The vulnerability is a Server‑Side Template Injection in the `trestle author jinja` command, causing the tool to recursively recompile and render already rendered output. By injecting malicious Jinja payloads into data fields such as SSP documents or lookup tables, an attacker can cause the tool to execute arbitrary commands with the privileges of the running process. The vulnerable component does not require direct control of the template; only attacker‑controlled data rendered within a trusted template is sufficient.
Affected Systems
Affected versions are all releases of compliance‑trestle prior to 3.12.2 and 4.0.3. The patch is included in 3.12.3 and 4.0.3. The product is developed by oscal‑compass and used for compliance as code.
Risk and Exploitability
The CVSS score is 7.8. The EPSS score is unavailable, and the issue is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is an attacker who can supply untrusted data to the trestle author jinja command, which may be local or remote depending on how the tool is invoked. Successful exploitation would give the attacker full control of the host where compliance‑trestle is running.
OpenCVE Enrichment
Github GHSA