What is CVE-2026-46345?
CVE-2026-46345 is a path traversal vulnerability in compliance-trestle's `trestle author jinja` command via the `-o/--output` argument. An authenticated user can write files outside the workspace using sequences like `../`; users should update to versions 3.12.2 or 4.0.3.
Azərbaycanca: CVE-2026-46345, compliance-trestle alətində `trestle author jinja` əmrinin `-o/--output` arqumentində path traversal zəifliyidir. Bu, autentifikasiya olunmuş istifadəçiyə `../` keçidləri ilə iş sahəsi xaricində fayl yazmağa imkan verir; istifadəçilər 3.12.2 və ya 4.0.3 versiyalarına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
Does exploiting CVE-2026-46345 require authentication?
Yes, an authenticated user is required to exploit this path traversal vulnerability.
Which versions of compliance-trestle should users update to for mitigating CVE-2026-46345?
Users should update compliance-trestle to versions 3.12.2 or 4.0.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.