PT-2026-106254 · Docling · Docling
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Docling versions 2.107.0 through 2.120.2
Description
In the ODF backend, the software improperly handles the
xlink:href attribute of a draw:image element. When a referenced part is not found within the document archive, the image ref from odf image function in docling/backend/opendocument backend.py uses the attribute value as a filesystem path to read the file. This process occurs without scheme checks, extraction-directory confinement, or adherence to the enable local fetch and enable remote fetch settings used by other backends.An attacker can provide a crafted
.odt file containing an absolute path in the xlink:href attribute. If the target file is one that Pillow can decode as an image, its full contents are embedded in the resulting DoclingDocument and disclosed in HTML, Markdown, and JSON exports. Additionally, the behavior allows for a silent file-existence oracle, as the system can distinguish between existing and non-existing paths on the host filesystem.Recommendations
Update Docling to version 2.120.3.
As a temporary workaround, restrict the processing of
.odt files from untrusted sources until the update is applied.Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Docling