CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-105744

CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 8, 2026·7 min read·1 visit

Executive Summary (TL;DR)

A high-severity vulnerability in Docling's optional Tectonic rendering engine allows remote attackers to read arbitrary files, overwrite critical server assets, or execute arbitrary commands via crafted LaTeX inputs containing malicious TikZ macros.

Docling, a tool for parsing and processing diverse document formats, is vulnerable to arbitrary file read, arbitrary file write, and potential remote code execution (RCE) in versions 2.94.0 through 2.131.0. The vulnerability occurs when applications configure Docling to use the Tectonic engine for rendering TikZ diagrams into images. Because the compilation did not restrict hazardous TeX primitives or sandbox the environment, an attacker can supply crafted documents containing malicious TikZ definitions to access or modify local files and execute arbitrary commands under the privileges of the processing application.

Vulnerability Overview

The vulnerability tracked as CVE-2026-105744 resides within the document rendering functionality of Docling, a document processing library used in generative artificial intelligence ingestion pipelines. Specifically, the flaw exists within the component handling LaTeX rendering of TikZ diagrams. When an application opts into utilizing the Tectonic compilation engine, the process compiles arbitrary LaTeX inputs without sufficient isolation or restriction of hazardous TeX primitives. This failure enables unauthenticated remote attackers to execute arbitrary system commands, disclose local files, and modify local file paths.

Tectonic is integrated into Docling to provide high-quality rasterization and vector rendering of mathematical and structural TikZ blocks contained within parsed documents. However, compile-time components within TeX engines historically possess robust capabilities to read and write physical files to maintain compatibility with legacy TeX document structures. When Docling invokes the Tectonic engine, these capabilities remain active by default, exposing the local system hosting the converter process to complete compromise if the input sources originate from untrusted users.

The attack surface is localized to endpoints that ingest documents and render TikZ objects. By submitting a crafted document containing a malicious TikZ macro block, an attacker triggers the Tectonic compiler on the server. The execution occurs with the privileges of the parent Python process, allowing the attacker to interact directly with the local operating system.

Root Cause Analysis

The primary security flaw stems from the insecure default configuration and lack of sandboxing during the compilation of LaTeX documents via the Tectonic engine. Tectonic, like classical engines such as pdfTeX or XeTeX, implements built-in commands designed to interact with the host filesystem. Specifically, the file stream primitives \openin and \openout allow documents to establish input and output file descriptors on the local disk. Additionally, standard LaTeX commands like \input, \include, and \includegraphics let the engine reference external assets, leading to arbitrary path traversal if the inputs are not restricted.

In vulnerable versions of Docling, specifically versions between 2.94.0 and 2.132.0, the TectonicEngine in docling/backend/latex/engines/tectonic.py is initialized with the option allow_shell_escape=True by default. Under this configuration, the Tectonic process is executed with the command-line flag -Z shell-escape enabled. This flag permits the execution of the standard TeX \write18 primitive, which functions as a system shell command execution engine. Any shell utility requested through a \write18 macro is immediately invoked on the underlying server.

Because the Tectonic process was executed without the --untrusted constraint, the engine operated without file search limitations. Furthermore, there was no pre-validation of the raw LaTeX or TikZ blocks. This allowed raw inputs containing malicious primitives to be directly compiled, granting the compiler authorization to read any file the current operating system user had access to, write arbitrary payloads to writable directories, or execute arbitrary system utilities if shell escape was active.

Code Analysis

The official security patch introduced two critical defense layers to remediate the vulnerability. The first layer modifies the process creation arguments to enforce strict execution boundaries via the Tectonic binary CLI. The second layer introduces a static analysis filter using regular expressions to block known unsafe primitives before the compiler is invoked.

The vulnerable implementation of _build_command in docling/backend/latex/engines/tectonic.py did not restrict local file paths or external network requests. The patch refactored this function to implement strict isolation when shell escape is not explicitly enabled:

# Patched implementation in docling/backend/latex/engines/tectonic.py
def _build_command(self, tex_file: Path) -> list[str]:
    """Build the Tectonic command line for compiling ``tex_file``."""
    cmd = [str(self.binary_path)]
    if self.allow_shell_escape:
        # If shell escape is active, --untrusted cannot be used as it blocks execution
        cmd.extend(["-Z", "shell-escape"])
    else: 
        # Enforce strict local sandboxing and disable shell execution
        # --untrusted blocks file writing outside of working dir and blocks external paths
        # --only-cached prevents unauthorized network connections to remote TeX repositories
        cmd.append("--untrusted")
        cmd.append("--only-cached")
    cmd.append("--print")
    cmd.append(str(tex_file))
    return cmd

In addition to enforcing CLI sandboxing, the developers implemented a static validation pattern within the TectonicEngine class. The validator matches structural primitives and file inclusion commands to prevent path traversal attempts.

# Static regular expressions implemented in the patch
_PATH_ARGUMENT_PATTERN = re.compile(
    r"\\(?P<command>input|include|includegraphics|InputIfFileExists|graphicspath)"
    r"(?![A-Za-z])\*?(?:\s*\[[^\]]*\])?\s*\{*\s*(?P<path>[^{}\s]*)"
)
_FILE_PRIMITIVE_PATTERN = re.compile(
    r"\\(?P<command>openin|openout|XeTeXpicfile|XeTeXpdffile)(?![A-Za-z])"
)

The matching routine parses the input document string and detects if the document references absolute paths or uses traversal sequences like .. to access files outside the allocated working directory.

@classmethod
def _find_unsafe_construct(cls, text: str) -> str | None:
    """Return a description of the first outside file reference, if any."""
    primitive = cls._FILE_PRIMITIVE_PATTERN.search(text)
    if primitive is not None:
        return f"\\{primitive.group('command')}"
    for match in cls._PATH_ARGUMENT_PATTERN.finditer(text):
        path = match.group("path")
        if (
            path.startswith(("/", "\\", "~"))
            or re.match(r"[A-Za-z]:", path)
            or ".." in re.split(r"[/\\]", path)
        ):
            return f"\\{match.group('command')} with path {path!r}"
    return None

Exploitation Methodology

Exploitation of CVE-2026-105744 requires the target application to have configured the non-default Tectonic TikZ engine (tikz_engine="tectonic"). When this condition is met, an attacker can exploit the vulnerability by supplying a crafted LaTeX document or document format containing inline TikZ diagrams.

To achieve arbitrary file read, the attacker inserts standard file-inclusion macros into the TikZ nodes. When the compiler processes the macro, it reads the content of the target file and inserts it directly into the generated document as text, which is then rasterized. This enables the attacker to exfiltrate confidential files, such as environment variables, private keys, or system databases.

To write or overwrite local files, the attacker uses the TeX file-writing primitives. During compilation, the engine opens a file descriptor and writes the payload to disk. If the application environment permits writing to accessible directories, the attacker can drop executable payloads, web shells, or override configuration files to compromise host integrity.

Impact Assessment

The impact of this vulnerability is characterized by a complete compromise of the confidentiality, integrity, and availability of the local system environment running the Docling service. Under default system configurations where Docling is run with elevated shell escape permissions, an attacker can achieve unauthenticated remote code execution. This allows commands to be executed directly inside the system shell with the permissions of the application process.

If shell escape is disabled, the system remains vulnerable to arbitrary file write and arbitrary file read. The ability to write files inside the execution path can lead to second-order remote code execution, such as writing a malicious script into a shared import directory. The ability to read arbitrary local files allows attackers to bypass security boundaries, discover credentials, and extract application-specific secrets.

The Common Vulnerability Scoring System (CVSS) v3.1 base score is 7.5, reflecting high confidentiality, integrity, and availability impacts. The attack complexity is rated as high because the vulnerability is contingent on the application choosing the non-default Tectonic rendering engine.

Mitigation and Defense-in-Depth

The primary remediation strategy is upgrading the docling and docling-slim packages to version 2.132.0 or above. This version implements both the command-line isolation mechanisms and the static source filtering checks to limit the execution surface of Tectonic.

If upgrading is not immediately possible, organizations must implement strong mitigations. First, verify that the configuration does not utilize the Tectonic engine. Applications should use default rendering paths or safe alternative converters that do not parse arbitrary LaTeX macros.

Because TeX is a Turing-complete macro language, static validation of inputs is historically bypassable using dynamic string construction techniques like \csname. Therefore, applications must run Docling within an isolated sandbox environment, such as a containerized environment with restricted filesystem permissions, read-only system mounts, and minimal user privileges.

Fix Analysis (1)

Technical Appendix

CVSS Score
7.5/ 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected Systems

Docling Document Parsing Applications running Tectonic renderingDocling Slim installations with Tectonic engine enabled

Affected Versions Detail

Product
Affected Versions
Fixed Version
docling
docling-project
>= 2.94.0, < 2.132.02.132.0
docling-slim
docling-project
>= 2.94.0, < 2.132.02.132.0
AttributeDetail
CWE IDCWE-22, CWE-73, CWE-1188
Attack VectorNetwork
CVSS Score7.5 (High)
EPSS Score0.00304 (Percentile: 21.27%)
Exploit StatusProof of Concept (PoC) available
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1083File and Directory Discovery
Discovery
T1005Data from Local System
Collection
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The application fails to restrict directory paths or limit system command access when compiling untrusted LaTeX structures via the Tectonic rendering engine.

References & Sources

  • [1]Official Vendor Advisory (GHSA)
  • [2]Fix Commit (GitHub)
  • [3]NVD Entry

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•12 minutes ago•CVE-2026-105748
4.3

CVE-2026-105748: Local File Inclusion and Arbitrary File Disclosure in Docling Document Parser

A Local File Inclusion (LFI) and Arbitrary File Disclosure vulnerability exists in Docling and Docling Slim versions >= 2.16.0 up to 2.131.0. When parsing serialized DoclingDocument structures using the JSON input format, the backend fails to restrict image URI schemes, allowing remote attackers to retrieve local files and verify path existence on the host system during embedded document export.

Amit Schendel
Amit Schendel
0 views•5 min read
•about 2 hours ago•CVE-2026-105743
4.0

CVE-2026-105743: Server-Side Request Forgery Guard Bypass in Docling Document Conversion Engine

An SSRF guard bypass vulnerability in the Docling document conversion engine allows unauthenticated attackers to bypass internal IP access controls. The vulnerability exists due to a DNS rebinding Time-of-Check Time-of-Use (TOCTOU) condition, URL authority parsing inconsistencies, and unvalidated network requests triggered during headless browser page rendering.

Amit Schendel
Amit Schendel
3 views•6 min read
•about 3 hours ago•CVE-2026-105742
3.7

CVE-2026-105742: Sensitive Custom Header Leakage in Docling Image Resource Loader

A technical analysis of CVE-2026-105742 (GHSA-p3fw-7699-7926), a sensitive information disclosure vulnerability in the Docling document processing library. Vulnerable versions of Docling indiscriminately forward custom HTTP headers, such as authentication tokens, to arbitrary third-party origins and during cross-origin redirects while fetching remote image assets from untrusted HTML and EPUB documents.

Alon Barad
Alon Barad
5 views•6 min read
•about 4 hours ago•CVE-2026-106121
4.9

CVE-2026-106121: Denial of Service via Infinite Loop in RabbitMQ Java Client JSON Parser

CVE-2026-106121 is a Denial of Service (DoS) vulnerability in the RabbitMQ Java Client library (amqp-client) affecting versions prior to 5.37.0. The vulnerability resides in the legacy, custom JSON-RPC parsing class com.rabbitmq.tools.json.JSONReader. When parsing malformed or truncated payloads ending within a quoted string or single-line comment, the parser's scanner enters an infinite loop. This occurs because the loop lacks an exit condition for the end-of-input sentinel character returned by the iterator, leading to either CPU exhaustion or a JVM crash from an OutOfMemoryError.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 6 hours ago•CVE-2026-105646
4.9

CVE-2026-105646: Regular Expression Denial of Service in Ghost CMS Import Handlers

An authenticated Regular Expression Denial of Service (ReDoS) vulnerability in TryGhost Ghost (CMS) versions 4.0.0 through 6.66.x. An attacker with administrator privileges can upload crafted content import archives containing pathological directory names or migration patterns, triggering exponential backtracking in the Node.js V8 engine.

Alon Barad
Alon Barad
8 views•6 min read
•about 7 hours ago•CVE-2026-105645
4.9

CVE-2026-105645: Regular Expression Denial of Service (ReDoS) in Ghost CMS

CVE-2026-105645 is a regular expression denial of service (ReDoS) vulnerability affecting Ghost, an open-source Node.js content management system. The vulnerability exists within directory import handlers and the external media inliner, allowing authenticated administrators to trigger catastrophic backtracking in the V8 JavaScript engine, resulting in infinite loops, 100% CPU utilization, and total denial of service.

Amit Schendel
Amit Schendel
8 views•6 min read