CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-105748

CVE-2026-105748: Local File Inclusion and Arbitrary File Disclosure in Docling Document Parser

Amit Schendel
Amit Schendel
Senior Security Researcher

Oct 8, 2026·5 min read·3 visits

Executive Summary (TL;DR)

Docling is vulnerable to Local File Inclusion via crafted JSON inputs, allowing attackers to read local system images or verify file existence.

A Local File Inclusion (LFI) and Arbitrary File Disclosure vulnerability exists in Docling and Docling Slim versions >= 2.16.0 up to 2.131.0. When parsing serialized DoclingDocument structures using the JSON input format, the backend fails to restrict image URI schemes, allowing remote attackers to retrieve local files and verify path existence on the host system during embedded document export.

Vulnerability Overview

The Docling document conversion library offers capabilities for parsing, structured layout extraction, and format conversions. It supports a declarative input schema via serialized JSON models, identified as the InputFormat.JSON_DOCLING backend. Within this input flow, the parser processes metadata structures including image definitions to rebuild or render document elements.

Historically, the parser accepted remote or local source references within its image schema without restricting the target protocols. This lack of restriction allows untrusted serialized JSON payloads to specify local file paths. Because the system subsequently attempts to access and embed these image references during export, it exposes the host system to Local File Inclusion (LFI).

An attacker can exploit this behavior by passing a crafted JSON document containing arbitrary local system file paths. The impact spans beyond file reading, allowing path validation, file existence mapping, and, under specific conditions, full exfiltration of sensitive graphical or binary files. The vulnerability exposes any deployment where Docling processes untrusted documents on a server-side backend.

Root Cause Analysis

The root cause lies in how Docling resolves asset URI schemes during its export pipeline. When a client imports a document using InputFormat.JSON_DOCLING, the backend deserializes the payload into Pydantic models. Within this model hierarchy, ImageRef objects represent individual images and store their locations in a uri property.

When exporting the parsed document using an embedded image mode (such as ImageRefMode.EMBEDDED), the engine calls internal resolution routines. Specifically, the method DoclingDocument._with_embedded_pictures delegates to ImageRef.pil_image to fetch the source asset. Because the uri property lacked validation filters, it can point directly to local filesystem paths.

The library resolves the path and invokes the Pillow (PIL) library's Image.open method. If the file is a valid image, Pillow reads its binary contents, which are subsequently Base64-encoded and outputted. If the path exists but fails image validation, or does not exist, the server throws specific exceptions. An attacker can analyze these error variations to discover file existence and directories.

Code Analysis

The vulnerability was addressed by introducing input sanitization filters within the JSON ingestion backend. In vulnerable versions, deserialization parsed the model directly and preserved local file paths in the ImageRef.uri fields without verification.

The remediation patch introduces the function _clear_local_image_refs inside docling/backend/json/docling_json_backend.py. This helper recurses down the entire Pydantic object hierarchy to find ImageRef instances. If the schema validator detects an asset URI that does not conform to a whitelisted secure remote scheme, the URI is wiped and set to None.

_KEPT_IMAGE_URI_SCHEMES = frozenset({"data", "http", "https"})
 
def _is_kept_image_uri(uri: AnyUrl | Path) -> bool:
    # Restrict URIs to whitelisted web protocols
    return isinstance(uri, AnyUrl) and uri.scheme.lower() in _KEPT_IMAGE_URI_SCHEMES
 
def _clear_local_image_refs(node: object) -> int:
    cleared = 0
    if isinstance(node, BaseModel):
        for name, value in node:
            if isinstance(value, ImageRef):
                if not _is_kept_image_uri(value.uri):
                    # Strips local files or unapproved schemes by replacing with None
                    setattr(node, name, None)
                    cleared += 1
            else:
                cleared += _clear_local_image_refs(value)
    # Tree-walking continues for list, tuple, and dict structures
    return cleared

This defensive filter blocks local paths from propagating into the core export engines. By applying this logic during initial JSON loading, downstream processes cannot trigger local image rendering.

Exploitation Methodology

Exploitation requires that an application ingest an attacker-controlled JSON file and export it using embedded graphics. Because the attack utilizes standard parser functions, the adversary needs no privileges on the target environment.

An attacker constructs a payload targeting local configurations, keys, or screenshots stored as images on the host filesystem. An example target path is /opt/app/sensitive_system_graphic.png or directories containing readable administrative assets.

{
  "schema_name": "DoclingDocument",
  "version": "1.0.0",
  "name": "Exploit payload",
  "pictures": [
    {
      "image": {
        "mimetype": "image/png",
        "dpi": 72,
        "size": {"width": 100, "height": 100},
        "uri": "/opt/app/sensitive_system_graphic.png"
      }
    }
  ]
}

When the converter processes this file and converts it into markdown with embedded objects, it writes out the Base64 representation of the file. The attacker receives this serialized output, decodes it, and recovers the target image. If non-image files are targeted, the application might return diagnostic error logs that reveal the presence or absence of the files, exposing a secondary path existence verification vulnerability.

Residual Risks and Security Gaps

A major residual risk exists for applications interacting directly with low-level components. The remediation code resides inside the docling high-level backend parser package, rather than the core schema definitions of docling-core.

If a developer ingests JSON directly using DoclingDocument.model_validate_json or similar schema-level methods in docling-core, the input sanitization filters are completely bypassed. Because the core library is unpatched, downstream pipelines operating directly on the schema remain vulnerable to the same local file exposure vector.

Additionally, the default protocol whitelist permits http and https schemas. This configuration exposes the server to Server-Side Request Forgery (SSRF) threats. An attacker can reference internal addresses or metadata endpoints, causing the host server to fetch local sensitive details or probe internal networks.

http://169.254.169.254/latest/meta-data/

Lastly, parser inconsistencies between Pydantic's AnyUrl parsing and the operating system's file resolver could lead to bypasses. For instance, Windows UNC paths or local administrative paths might elude the standard scheme filters but still trigger file access when handled by Python's underlying file APIs.

Fix Analysis (1)

Technical Appendix

CVSS Score
4.3/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS Probability
0.22%
Top 89% most exploited

Affected Systems

docling-project/doclingdocling-project/docling-slim

Affected Versions Detail

Product
Affected Versions
Fixed Version
docling
docling-project
>= 2.16.0, < 2.131.02.131.0
docling-slim
docling-project
>= 2.16.0, < 2.131.02.131.0
AttributeDetail
CWE IDCWE-73 (External Control of File Name or Path)
Attack VectorNetwork
CVSS Score4.3 (Medium)
EPSS Score0.00218
ImpactLow Confidentiality (Local File Inclusion / Path Probing)
Exploit StatusPoC / Non-weaponized
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1005Data from Local System
Collection
T1552Unsecured Credentials
Credential Access
CWE-73
External Control of File Name or Path

The software allows user input to control paths or filenames, leading to unauthorized access to local filesystem resources.

References & Sources

  • [1]GitHub Security Advisory
  • [2]Official Fix Commit
  • [3]Official Pull Request
  • [4]Release Notes (v2.131.0)
  • [5]National Vulnerability Database (NVD)

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•13 minutes ago•CVE-2026-105749
6.5

CVE-2026-105749: Unbounded Table Attributes in Docling Backends Leads to Resource Exhaustion

An uncontrolled resource consumption vulnerability exists in the Docling document conversion library. Maliciously structured HTML, JATS, ODS, or BoxNote inputs containing table cells with excessively large 'rowspan' or 'colspan' attribute values trigger algorithmic complexity conditions. This allows unauthenticated remote attackers to initiate resource exhaustion states, crashing or hanging the target document processing pipeline while bypassing configured timeouts.

Amit Schendel
Amit Schendel
0 views•6 min read
•about 2 hours ago•CVE-2026-105744
7.5

CVE-2026-105744: Arbitrary File Read and Remote Code Execution in Docling Tectonic Engine

Docling, a tool for parsing and processing diverse document formats, is vulnerable to arbitrary file read, arbitrary file write, and potential remote code execution (RCE) in versions 2.94.0 through 2.131.0. The vulnerability occurs when applications configure Docling to use the Tectonic engine for rendering TikZ diagrams into images. Because the compilation did not restrict hazardous TeX primitives or sandbox the environment, an attacker can supply crafted documents containing malicious TikZ definitions to access or modify local files and execute arbitrary commands under the privileges of the processing application.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 3 hours ago•CVE-2026-105743
4.0

CVE-2026-105743: Server-Side Request Forgery Guard Bypass in Docling Document Conversion Engine

An SSRF guard bypass vulnerability in the Docling document conversion engine allows unauthenticated attackers to bypass internal IP access controls. The vulnerability exists due to a DNS rebinding Time-of-Check Time-of-Use (TOCTOU) condition, URL authority parsing inconsistencies, and unvalidated network requests triggered during headless browser page rendering.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 4 hours ago•CVE-2026-105742
3.7

CVE-2026-105742: Sensitive Custom Header Leakage in Docling Image Resource Loader

A technical analysis of CVE-2026-105742 (GHSA-p3fw-7699-7926), a sensitive information disclosure vulnerability in the Docling document processing library. Vulnerable versions of Docling indiscriminately forward custom HTTP headers, such as authentication tokens, to arbitrary third-party origins and during cross-origin redirects while fetching remote image assets from untrusted HTML and EPUB documents.

Alon Barad
Alon Barad
5 views•6 min read
•about 5 hours ago•CVE-2026-106121
4.9

CVE-2026-106121: Denial of Service via Infinite Loop in RabbitMQ Java Client JSON Parser

CVE-2026-106121 is a Denial of Service (DoS) vulnerability in the RabbitMQ Java Client library (amqp-client) affecting versions prior to 5.37.0. The vulnerability resides in the legacy, custom JSON-RPC parsing class com.rabbitmq.tools.json.JSONReader. When parsing malformed or truncated payloads ending within a quoted string or single-line comment, the parser's scanner enters an infinite loop. This occurs because the loop lacks an exit condition for the end-of-input sentinel character returned by the iterator, leading to either CPU exhaustion or a JVM crash from an OutOfMemoryError.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 7 hours ago•CVE-2026-105646
4.9

CVE-2026-105646: Regular Expression Denial of Service in Ghost CMS Import Handlers

An authenticated Regular Expression Denial of Service (ReDoS) vulnerability in TryGhost Ghost (CMS) versions 4.0.0 through 6.66.x. An attacker with administrator privileges can upload crafted content import archives containing pathological directory names or migration patterns, triggering exponential backtracking in the Node.js V8 engine.

Alon Barad
Alon Barad
8 views•6 min read