THREAT OPS › Threat News › [GHSA] GHSA-jw39-3688-r4rx (high) — Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
[GHSA] GHSA-jw39-3688-r4rx (high) — Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
GHSA-jw39-3688-r4rx Severity: high CVE: CVE-2026-54757
Trestle has Server-Side Template Injection (SSTI) via Recursive Template Re-evaluation of Untrusted Data
### Impact
A Server-Side Template Injection (SSTI) vulnerability exists in multiple locations of trestle's Jinja2 rendering pipeline due to a systemic pattern: **untrusted data is re-parsed as Jinja2 template source code without sandboxi
MITRE ATT&CK techniques
- Template InjectionT1221
Indicators of compromise
- CVE-2026-54757cve
Original source: https://github.com/advisories/GHSA-jw39-3688-r4rx