Oct 8, 2026·7 min read·1 visit
A high-severity vulnerability in Docling's optional Tectonic rendering engine allows remote attackers to read arbitrary files, overwrite critical server assets, or execute arbitrary commands via crafted LaTeX inputs containing malicious TikZ macros.
Docling, a tool for parsing and processing diverse document formats, is vulnerable to arbitrary file read, arbitrary file write, and potential remote code execution (RCE) in versions 2.94.0 through 2.131.0. The vulnerability occurs when applications configure Docling to use the Tectonic engine for rendering TikZ diagrams into images. Because the compilation did not restrict hazardous TeX primitives or sandbox the environment, an attacker can supply crafted documents containing malicious TikZ definitions to access or modify local files and execute arbitrary commands under the privileges of the processing application.
The vulnerability tracked as CVE-2026-105744 resides within the document rendering functionality of Docling, a document processing library used in generative artificial intelligence ingestion pipelines. Specifically, the flaw exists within the component handling LaTeX rendering of TikZ diagrams. When an application opts into utilizing the Tectonic compilation engine, the process compiles arbitrary LaTeX inputs without sufficient isolation or restriction of hazardous TeX primitives. This failure enables unauthenticated remote attackers to execute arbitrary system commands, disclose local files, and modify local file paths.
Tectonic is integrated into Docling to provide high-quality rasterization and vector rendering of mathematical and structural TikZ blocks contained within parsed documents. However, compile-time components within TeX engines historically possess robust capabilities to read and write physical files to maintain compatibility with legacy TeX document structures. When Docling invokes the Tectonic engine, these capabilities remain active by default, exposing the local system hosting the converter process to complete compromise if the input sources originate from untrusted users.
The attack surface is localized to endpoints that ingest documents and render TikZ objects. By submitting a crafted document containing a malicious TikZ macro block, an attacker triggers the Tectonic compiler on the server. The execution occurs with the privileges of the parent Python process, allowing the attacker to interact directly with the local operating system.
The primary security flaw stems from the insecure default configuration and lack of sandboxing during the compilation of LaTeX documents via the Tectonic engine. Tectonic, like classical engines such as pdfTeX or XeTeX, implements built-in commands designed to interact with the host filesystem. Specifically, the file stream primitives \openin and \openout allow documents to establish input and output file descriptors on the local disk. Additionally, standard LaTeX commands like \input, \include, and \includegraphics let the engine reference external assets, leading to arbitrary path traversal if the inputs are not restricted.
In vulnerable versions of Docling, specifically versions between 2.94.0 and 2.132.0, the TectonicEngine in docling/backend/latex/engines/tectonic.py is initialized with the option allow_shell_escape=True by default. Under this configuration, the Tectonic process is executed with the command-line flag -Z shell-escape enabled. This flag permits the execution of the standard TeX \write18 primitive, which functions as a system shell command execution engine. Any shell utility requested through a \write18 macro is immediately invoked on the underlying server.
Because the Tectonic process was executed without the --untrusted constraint, the engine operated without file search limitations. Furthermore, there was no pre-validation of the raw LaTeX or TikZ blocks. This allowed raw inputs containing malicious primitives to be directly compiled, granting the compiler authorization to read any file the current operating system user had access to, write arbitrary payloads to writable directories, or execute arbitrary system utilities if shell escape was active.
The official security patch introduced two critical defense layers to remediate the vulnerability. The first layer modifies the process creation arguments to enforce strict execution boundaries via the Tectonic binary CLI. The second layer introduces a static analysis filter using regular expressions to block known unsafe primitives before the compiler is invoked.
The vulnerable implementation of _build_command in docling/backend/latex/engines/tectonic.py did not restrict local file paths or external network requests. The patch refactored this function to implement strict isolation when shell escape is not explicitly enabled:
# Patched implementation in docling/backend/latex/engines/tectonic.py
def _build_command(self, tex_file: Path) -> list[str]:
"""Build the Tectonic command line for compiling ``tex_file``."""
cmd = [str(self.binary_path)]
if self.allow_shell_escape:
# If shell escape is active, --untrusted cannot be used as it blocks execution
cmd.extend(["-Z", "shell-escape"])
else:
# Enforce strict local sandboxing and disable shell execution
# --untrusted blocks file writing outside of working dir and blocks external paths
# --only-cached prevents unauthorized network connections to remote TeX repositories
cmd.append("--untrusted")
cmd.append("--only-cached")
cmd.append("--print")
cmd.append(str(tex_file))
return cmdIn addition to enforcing CLI sandboxing, the developers implemented a static validation pattern within the TectonicEngine class. The validator matches structural primitives and file inclusion commands to prevent path traversal attempts.
# Static regular expressions implemented in the patch
_PATH_ARGUMENT_PATTERN = re.compile(
r"\\(?P<command>input|include|includegraphics|InputIfFileExists|graphicspath)"
r"(?![A-Za-z])\*?(?:\s*\[[^\]]*\])?\s*\{*\s*(?P<path>[^{}\s]*)"
)
_FILE_PRIMITIVE_PATTERN = re.compile(
r"\\(?P<command>openin|openout|XeTeXpicfile|XeTeXpdffile)(?![A-Za-z])"
)The matching routine parses the input document string and detects if the document references absolute paths or uses traversal sequences like .. to access files outside the allocated working directory.
@classmethod
def _find_unsafe_construct(cls, text: str) -> str | None:
"""Return a description of the first outside file reference, if any."""
primitive = cls._FILE_PRIMITIVE_PATTERN.search(text)
if primitive is not None:
return f"\\{primitive.group('command')}"
for match in cls._PATH_ARGUMENT_PATTERN.finditer(text):
path = match.group("path")
if (
path.startswith(("/", "\\", "~"))
or re.match(r"[A-Za-z]:", path)
or ".." in re.split(r"[/\\]", path)
):
return f"\\{match.group('command')} with path {path!r}"
return NoneExploitation of CVE-2026-105744 requires the target application to have configured the non-default Tectonic TikZ engine (tikz_engine="tectonic"). When this condition is met, an attacker can exploit the vulnerability by supplying a crafted LaTeX document or document format containing inline TikZ diagrams.
To achieve arbitrary file read, the attacker inserts standard file-inclusion macros into the TikZ nodes. When the compiler processes the macro, it reads the content of the target file and inserts it directly into the generated document as text, which is then rasterized. This enables the attacker to exfiltrate confidential files, such as environment variables, private keys, or system databases.
To write or overwrite local files, the attacker uses the TeX file-writing primitives. During compilation, the engine opens a file descriptor and writes the payload to disk. If the application environment permits writing to accessible directories, the attacker can drop executable payloads, web shells, or override configuration files to compromise host integrity.
The impact of this vulnerability is characterized by a complete compromise of the confidentiality, integrity, and availability of the local system environment running the Docling service. Under default system configurations where Docling is run with elevated shell escape permissions, an attacker can achieve unauthenticated remote code execution. This allows commands to be executed directly inside the system shell with the permissions of the application process.
If shell escape is disabled, the system remains vulnerable to arbitrary file write and arbitrary file read. The ability to write files inside the execution path can lead to second-order remote code execution, such as writing a malicious script into a shared import directory. The ability to read arbitrary local files allows attackers to bypass security boundaries, discover credentials, and extract application-specific secrets.
The Common Vulnerability Scoring System (CVSS) v3.1 base score is 7.5, reflecting high confidentiality, integrity, and availability impacts. The attack complexity is rated as high because the vulnerability is contingent on the application choosing the non-default Tectonic rendering engine.
The primary remediation strategy is upgrading the docling and docling-slim packages to version 2.132.0 or above. This version implements both the command-line isolation mechanisms and the static source filtering checks to limit the execution surface of Tectonic.
If upgrading is not immediately possible, organizations must implement strong mitigations. First, verify that the configuration does not utilize the Tectonic engine. Applications should use default rendering paths or safe alternative converters that do not parse arbitrary LaTeX macros.
Because TeX is a Turing-complete macro language, static validation of inputs is historically bypassable using dynamic string construction techniques like \csname. Therefore, applications must run Docling within an isolated sandbox environment, such as a containerized environment with restricted filesystem permissions, read-only system mounts, and minimal user privileges.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H| Product | Affected Versions | Fixed Version |
|---|---|---|
docling docling-project | >= 2.94.0, < 2.132.0 | 2.132.0 |
docling-slim docling-project | >= 2.94.0, < 2.132.0 | 2.132.0 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-22, CWE-73, CWE-1188 |
| Attack Vector | Network |
| CVSS Score | 7.5 (High) |
| EPSS Score | 0.00304 (Percentile: 21.27%) |
| Exploit Status | Proof of Concept (PoC) available |
| CISA KEV Status | Not Listed |
The application fails to restrict directory paths or limit system command access when compiling untrusted LaTeX structures via the Tectonic rendering engine.
A Local File Inclusion (LFI) and Arbitrary File Disclosure vulnerability exists in Docling and Docling Slim versions >= 2.16.0 up to 2.131.0. When parsing serialized DoclingDocument structures using the JSON input format, the backend fails to restrict image URI schemes, allowing remote attackers to retrieve local files and verify path existence on the host system during embedded document export.
An SSRF guard bypass vulnerability in the Docling document conversion engine allows unauthenticated attackers to bypass internal IP access controls. The vulnerability exists due to a DNS rebinding Time-of-Check Time-of-Use (TOCTOU) condition, URL authority parsing inconsistencies, and unvalidated network requests triggered during headless browser page rendering.
A technical analysis of CVE-2026-105742 (GHSA-p3fw-7699-7926), a sensitive information disclosure vulnerability in the Docling document processing library. Vulnerable versions of Docling indiscriminately forward custom HTTP headers, such as authentication tokens, to arbitrary third-party origins and during cross-origin redirects while fetching remote image assets from untrusted HTML and EPUB documents.
CVE-2026-106121 is a Denial of Service (DoS) vulnerability in the RabbitMQ Java Client library (amqp-client) affecting versions prior to 5.37.0. The vulnerability resides in the legacy, custom JSON-RPC parsing class com.rabbitmq.tools.json.JSONReader. When parsing malformed or truncated payloads ending within a quoted string or single-line comment, the parser's scanner enters an infinite loop. This occurs because the loop lacks an exit condition for the end-of-input sentinel character returned by the iterator, leading to either CPU exhaustion or a JVM crash from an OutOfMemoryError.
An authenticated Regular Expression Denial of Service (ReDoS) vulnerability in TryGhost Ghost (CMS) versions 4.0.0 through 6.66.x. An attacker with administrator privileges can upload crafted content import archives containing pathological directory names or migration patterns, triggering exponential backtracking in the Node.js V8 engine.
CVE-2026-105645 is a regular expression denial of service (ReDoS) vulnerability affecting Ghost, an open-source Node.js content management system. The vulnerability exists within directory import handlers and the external media inliner, allowing authenticated administrators to trigger catastrophic backtracking in the V8 JavaScript engine, resulting in infinite loops, 100% CPU utilization, and total denial of service.