CVE-2026-45774 | oscal-compass compliance-trestle up to 3.12.1/4.0.2 Profile Import Mechanism resolve imports[].href path traversal

SecurityVulns

A vulnerability labeled as problematic has been found in oscal-compass compliance-trestle up to 3.12.1/4.0.2. Impacted is the function resolve of the component Profile Import Mechanism. Executing a manipulation of the argument imports[].href can lead to path traversal.

This vulnerability is tracked as CVE-2026-45774. The attack can be launched remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More