A vulnerability has been found in oscal-compass compliance-trestle up to 3.12.1/4.0.2 and classified as problematic. Impacted is the function trestle author jinja of the component Jinja. This manipulation causes improper neutralization of special elements used in a template engine.

This vulnerability appears as CVE-2026-46439. The attack requires local access. There is no available exploit.

The affected component should be upgraded.