Vulnerabilidades en oscal-compass
9 resultadosAnálisis Vexday
O oscal-compass apresenta 5 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando exposição recente e concentrada. Não há registros de exploração ativa em campo (KEV) nem vulnerabilidades críticas, mas a dominância de CWE-22 (Path Traversal) sugere fraqueza estrutural em validação de caminhos de arquivo que merece atenção em avaliações de segurança.
CVE-2026-45774MEDIUMcompliance-trestle Profile Import has an Arbitrary File Read via trestle:// URI and Relative Path TraversalEPSS 0.5%CVE-2026-52776HIGHTrestle URLSecurityValidator SSRF allowlist bypass via IPv4-mapped IPv6 and 0.0.0.0EPSS 0.4%CVE-2026-45725HIGHcompliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path TraversalEPSS 0.3%CVE-2026-54757HIGHTrestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted DataEPSS 0.2%CVE-2026-46439HIGHcompliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)EPSS 0.2%CVE-2026-46345HIGHcompliance-trestle - jinja has an Arbitrary File Write via Path TraversalEPSS 0.2%CVE-2026-57170HIGHTrestle SSTI in Jinja2 include tags allows arbitrary code execution (Incomplete fix of CVE-2026-46439)EPSS 0.2%CVE-2026-57171HIGHTrestle is vulnerable to arbitrary file write via path traversal in author generate commands (Incomplete fix of CVE-2026-46345)EPSS 0.2%CVE-2026-46380MEDIUMcompliance-trestle Vulnerable to SSRF in Remote Fetching SubsystemEPSS 0.2%