THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jw39-3688-r4rx (high) — Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

[GHSA] GHSA-jw39-3688-r4rx (high) — Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

medgithub_advisoriesPublished 2026-08-28

GHSA-jw39-3688-r4rx Severity: high CVE: CVE-2026-54757

Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data

### Impact

A Server-Side Template Injection (SSTI) vulnerability exists in multiple locations of trestle's Jinja2 rendering pipeline due to a systemic pattern: **untrusted data is re-parsed as Jinja2 template source code without sandboxi

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jw39-3688-r4rx