A vulnerability has been found in oscal-compass compliance-trestle up to 3.12.1/4.0.2 and classified as problematic. Impacted is the function
trestle author jinja of the component Jinja. This manipulation causes improper neutralization of special elements used in a template engine.
This vulnerability appears as CVE-2026-46439. The attack requires local access. There is no available exploit.
The affected component should be upgraded.