HIGH8.4CVE-2026-46345compliance-trestle - jinja has an Arbitrary File Write via Path Traversal >= 4.0.0, < 4.0.3
HIGH8.4CVE-2026-46345compliance-trestle - jinja has an Arbitrary File Write via Path Traversal from 0, < 3.12.2, >= 4.0.0, < 4.0.3
HIGH7.8CVE-2026-46439compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI) from 0, < 3.12.2
HIGH7.8compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
from 0, < 3.12.2, >= 4.0.0, < 4.0.3
MEDIUM6.7compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
>= 4.0.0, < 4.0.3
MEDIUM6.7compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem
from 0, < 3.12.2, >= 4.0.0, < 4.0.3
—compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal
>= 4.0.0, < 4.0.3
—compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal
from 0, < 3.12.2, >= 4.0.0, < 4.0.3
—compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal
>= 4.0.0, < 4.0.3
—compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal
from 0, < 3.12.2, >= 4.0.0, < 4.0.3