PT-2026-106254 · Docling · Docling

·

CVE-2026-105751

·

Published

2026-10-05

·

Updated

2026-10-05

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Docling versions 2.107.0 through 2.120.2
Description In the ODF backend, the software improperly handles the xlink:href attribute of a draw:image element. When a referenced part is not found within the document archive, the image ref from odf image function in docling/backend/opendocument backend.py uses the attribute value as a filesystem path to read the file. This process occurs without scheme checks, extraction-directory confinement, or adherence to the enable local fetch and enable remote fetch settings used by other backends.
An attacker can provide a crafted .odt file containing an absolute path in the xlink:href attribute. If the target file is one that Pillow can decode as an image, its full contents are embedded in the resulting DoclingDocument and disclosed in HTML, Markdown, and JSON exports. Additionally, the behavior allows for a silent file-existence oracle, as the system can distinguish between existing and non-existing paths on the host filesystem.
Recommendations Update Docling to version 2.120.3. As a temporary workaround, restrict the processing of .odt files from untrusted sources until the update is applied.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105751
GHSA-4XHP-XG4W-8PPM

Affected Products

Docling