Vulnerabilities

Last updated 45 minutes ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
compliance-trestle Trestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439) High Risk 7.8 3 days ago 3 days ago
compliance-trestle Trestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345) High Risk 8.4 3 days ago 3 days ago
compliance-trestle Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data High Risk 7.8 1 month ago 18 days ago
compliance-trestle Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data High Risk 7.8 18 days ago 18 days ago
compliance-trestle compliance-trestle - jinja has an Arbitrary File Write via Path Traversal High Risk 8.4 4 months ago 1 month ago
compliance-trestle compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 High Risk 8.0 1 month ago 1 month ago
compliance-trestle compliance-trestle has an URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0 Unknown 1 month ago 1 month ago
compliance-trestle compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal High Risk 8.0 4 months ago 2 months ago
compliance-trestle compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem Medium Risk 6.7 4 months ago 2 months ago
compliance-trestle compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal Medium Risk 6.0 4 months ago 2 months ago
compliance-trestle compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI) High Risk 7.8 4 months ago 2 months ago
compliance-trestle compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal Unknown 2 months ago 2 months ago
compliance-trestle compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI) High Risk 7.8 2 months ago 2 months ago
compliance-trestle compliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path Traversal Unknown 2 months ago 2 months ago
compliance-trestle compliance-trestle Vulnerable to SSRF in Remote Fetching Subsystem Medium Risk 6.7 2 months ago 2 months ago
compliance-trestle compliance-trestle - jinja has an Arbitrary File Write via Path Traversal High Risk 8.4 2 months ago 2 months ago