CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-105750

CVE-2026-105750: Local File Disclosure in Docling via Permissive HTML Rendering Requests Filter

Alon Barad
Alon Barad
Software Engineer

Oct 6, 2026·7 min read·9 visits

Executive Summary (TL;DR)

A validation flaw in Docling's HTML rendering backend allows local file disclosure (LFD) when processing untrusted HTML files using Playwright.

CVE-2026-105750 is a medium-severity local file disclosure vulnerability affecting the Docling and Docling-Slim libraries. When processing HTML documents using the optional Playwright rendering backend, the application fail to validate and restrict request URIs using the file:// scheme. This permits an attacker supplying a crafted HTML file to access, render, and exfiltrate local system files.

Vulnerability Overview

Docling and Docling-Slim are specialized Python libraries used in modern data-engineering pipelines to parse, structure, and convert document formats such as PDFs, Office files, and HTML into structured JSON or Markdown. To support downstream generative AI pipelines and Retrieval-Augmented Generation (RAG) tasks, the library offers a visual page-rendering mode using a headless browser. When configured with HTMLBackendOptions(render_page=True) and with Playwright installed, the backend spawns a browser context to capture precise layout structures, visual elements, and embedded styling.

To restrict the browser context from accessing unauthorized network or filesystem assets, the application implements custom request filtering. The core of this mechanism resides within the HTMLDocumentBackend._get_browser_request_block_reason method, which dynamically inspects each URI request initiated by the browser during parsing. In vulnerable versions starting from 2.82.0 up to but not including 2.118.1, this filter permitted local directory and scheme access without sufficient constraints.

Specifically, the implementation unconditionally approved requests utilizing the file:// scheme, allowing the browser engine to query any absolute path on the host filesystem that was accessible to the running process. When a document is processed from a local filesystem path, this gap allows malicious HTML documents to load, render, and exfiltrate highly sensitive files, such as Unix configurations or application database secrets, directly into the document layout structure.

Root Cause Analysis

The root cause of CVE-2026-105750 lies in a flawed authorization policy in the request interceptor of the HTML document rendering backend. When Playwright is instructed to render an HTML page, it registers a route handler to inspect every network and filesystem sub-request. The HTMLDocumentBackend._get_browser_request_block_reason method is invoked to evaluate if a request should be blocked based on security configurations.

In affected versions, the filter logic parsed the target URL and extracted the lowercase URI scheme. If the parsed scheme matched file, data, about, or blob, the function immediately returned None, which signifies that there is no block reason. This logic failed to account for the risk of local file extraction when rendering an untrusted local HTML document.

Because the browser executed within the server's context, any resource references using the file:// scheme were evaluated from the server's perspective. If an attacker could force the pipeline to process an HTML file via a filesystem Path input, the browser was granted full access to read local file paths via standard HTML embedding tags such as iframe, object, or link.

Crucially, this vulnerability is only exploitable when the file is parsed using a filesystem Path input rather than a memory stream. If a stream-based input is used, the browser executes the rendering process within an opaque origin context, which automatically restricts local file access due to standard browser-level sandbox policies. However, when a Path is used, the browser context inherits file system privileges relative to the document's location.

Code Analysis

To understand the vulnerability and its remediation, we must examine the changes made to docling/backend/html_backend.py in the fix commit 1612b8875b0937447ce3122536fb5360a7102a0a.

Prior to the patch, the block reasoning logic was highly permissive towards the file scheme:

def _get_browser_request_block_reason(self, request_url: str) -> Optional[str]:
    parsed = urlparse(request_url)
    scheme = (parsed.scheme or "").lower()
    # VULNERABLE: Unconditionally permitting file:// scheme requests
    if scheme in {"file", "data", "about", "blob"}:
        return None
 
    if ImageResourceLoader.is_remote_url(request_url):
        # ... remote validation checks ...

The patch resolved this by introducing two helpers: _get_browser_local_base_path and _is_allowed_browser_file_request. Together, they enforce strict confinement policies:

    def _get_browser_local_base_path(self) -> Optional[Path]:
        if isinstance(self.path_or_stream, Path):
            return self.path_or_stream.resolve()
 
        if self.base_path and ImageResourceLoader.is_local_path(self.base_path):
            return Path(self.base_path).resolve()
 
        return None
 
    def _is_allowed_browser_file_request(self, request_url: str) -> bool:
        local_base_path = self._get_browser_local_base_path()
        # Permit loading of the source document itself
        if local_base_path is not None and request_url == local_base_path.as_uri():
            return True
 
        # Restrict loading of sub-resources unless explicitly allowed and within path bounds
        if not self.options.enable_local_fetch or local_base_path is None:
            return False
 
        # Normalize path traversing patterns to prevent directory escape
        requested_path = Path(url2pathname(urlparse(request_url).path)).resolve()
        return requested_path.is_relative_to(local_base_path.parent)

With these changes, the modified filtering logic checks file requests against the allowed directory boundaries. It restricts file requests to the parent directory of the source HTML document being parsed. This prevents arbitrary directory traversal attacks using parent sequences or symbolic links.

Exploitation Methodology

Exploiting this vulnerability requires three prerequisites: the target system must have the Playwright dependency installed, the parsing pipeline must configure HTMLBackendOptions(render_page=True), and the application must receive and parse an HTML file path rather than a memory stream.

An attacker can construct a payload HTML document containing tags that reference target host files. For instance, embedding an <iframe> targeting file:///etc/passwd or /etc/resolv.conf forces the headless browser to retrieve these files during the document layout phase.

When the Docling pipeline processes this document, Playwright executes the parsing request, retrieves the targeted file, and renders its contents inside the output document layout structure. Because Docling extracts text content and layout structures from the rendered view, the contents of the target file are incorporated into the final processed output object.

<!DOCTYPE html>
<html>
<head>
    <title>Exploit Payload</title>
</head>
<body>
    <!-- Embed sensitive configuration file -->
    <iframe src="file:///etc/passwd" width="100%" height="600px"></iframe>
</body>
</html>

If the application returns the parsed output (such as converted Markdown or text layouts) to the user, the attacker can view the exact contents of the host file. This can lead to information disclosure of service credentials, environment variables, or critical system structures.

Impact Assessment

The impact of CVE-2026-105750 is classified as high confidentiality loss with a CVSS base score of 5.9. In typical server environments where Docling processes user-supplied documents, such as automated RAG pipelines, chatbots, or document analysis services, this flaw can expose sensitive local configurations.

If an application runs with elevated privileges, an attacker can extract system configuration files, cloud instance credentials (such as local metadata server keys), internal network details, and SSH keys. This data can facilitate lateral movement within the network or cloud environment.

Furthermore, because this flaw operates at the document layout engine layer, traditional input validation controls that only inspect raw text strings may fail to detect the visual file injection. The vulnerability does not affect system integrity or availability, as the execution bounds are restricted to read operations.

Remediation & Defense

To address this vulnerability, administrators and developers must upgrade the docling and docling-slim packages to version 2.118.1 or later. This version enforces path-confinement policies and disables local file loading by default.

pip install --upgrade docling docling-slim

If upgrading is not immediately possible, implement the following workarounds to reduce risk:

  1. Ensure that the enable_local_fetch option within HTMLBackendOptions is configured to False. This is the default setting and prevents the browser from making local filesystem requests during rendering.

  2. Avoid using the HTML rendering page option (render_page=True) when processing untrusted HTML files. Using non-rendering parser backends avoids initializing Playwright contexts, neutralizing the attack vector.

  3. Configure the parsing pipeline to receive inputs as memory streams (e.g., BytesIO) rather than local file system paths. Processing inputs as streams forces Playwright to operate within an opaque origin context, which prevents the loading of local file resources.

Official Patches

docling-projectCoordinated Vulnerability Disclosure (CVD) advisory and mitigation
docling-projectOfficial pull request containing security changes

Fix Analysis (1)

Technical Appendix

CVSS Score
5.9/ 10
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Systems

Docling document processing environments running with HTML rendering enabled

Affected Versions Detail

Product
Affected Versions
Fixed Version
docling
docling-project
>= 2.82.0, < 2.118.12.118.1
docling-slim
docling-project
>= 2.92.0, < 2.118.12.118.1
AttributeDetail
CWE IDCWE-863 / CWE-552
Attack VectorNetwork
CVSS Base Score5.9 (Medium)
Exploit StatusProof of Concept (PoC) available
CISA KEV StatusNo
Vulnerable Versions>= 2.82.0, < 2.118.1
Primary ImpactConfidentiality (Arbitrary Local File Disclosure)

MITRE ATT&CK Mapping

T1068Exploitation for Privilege Escalation
Privilege Escalation
CWE-863
Incorrect Authorization

The software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.

Vulnerability Timeline

Patches developed and committed to the main branch
2026-08-06
Official patched version v2.118.1 released
2026-10-05
GitHub Security Advisory published
2026-10-05
CVE-2026-105750 assigned and published
2026-10-05

References & Sources

  • [1]GitHub Security Advisory GHSA-q43m-vhcp-mhvm
  • [2]Fix Commit 1612b88
  • [3]Docling v2.118.1 Release

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•8 minutes ago•CVE-2026-102828
9.2

CVE-2026-102828: Remote Code Execution via Configuration and Argument Injection in simple-git

A critical remote code execution vulnerability (CVE-2026-102828) exists in simple-git versions 3.15.0 through 4.0.0. The vulnerability is caused by an incomplete blocklist within the library's default safety enforcement plugin, blockUnsafeOperationsPlugin. Attackers who can control Git configuration arguments or supply command flags to rebase operations can execute arbitrary system commands with the privileges of the parent Node.js process.

Amit Schendel
Amit Schendel
0 views•5 min read
•about 1 hour ago•CVE-2026-102829
9.2

CVE-2026-102829: Security Control Bypass and Command Injection via VISUAL Environment Variable in @simple-git/argv-parser

A critical security control bypass vulnerability exists in @simple-git/argv-parser before version 2.0.1. The package fails to map the VISUAL environment variable to the allowUnsafeEditor rule, allowing attackers who control environment parameters to execute arbitrary commands when Git triggers an interactive editor fallback.

Alon Barad
Alon Barad
4 views•5 min read
•about 2 hours ago•CVE-2026-105752
3.1

CVE-2026-105752: Cross-Tenant Prefix-Cache Information Leak via Cache Salt Omission in vLLM Harmony Path

A vulnerability in vLLM prior to 0.30.0 allows an authenticated multi-tenant attacker to infer execution history and prompt structures of other tenants. The multi-turn Responses API ('Harmony' path) fails to propagate the 'cache_salt' parameter during tool-call continuation steps, storing sensitive prompt prefixes in the global, unsalted cache space.

Alon Barad
Alon Barad
8 views•7 min read
•about 3 hours ago•CVE-2026-105753
6.5

CVE-2026-105753: Reachable Assertion in vLLM Multimodal IPC Cache Leading to Denial of Service

A state desynchronization (cache drift) vulnerability exists in the multimodal Inter-Process Communication (IPC) Least Recently Used (LRU) caches of vLLM. When a multimodal request fails validation after its media hash has been registered on the frontend but before the payload is committed to the backend engine core, the frontend and backend caches drift out of lockstep. A subsequent request reusing the same media triggers an assertion failure in the backend engine core, resulting in a complete denial of service.

Alon Barad
Alon Barad
8 views•5 min read
•about 5 hours ago•CVE-2026-102598
6.3

CVE-2026-102598: Remote Denial of Service via NTFS Alternate Data Stream Bypass in Werkzeug safe_join

CVE-2026-102598 is a security bypass and Denial of Service (DoS) vulnerability in the Werkzeug WSGI web application library. In versions prior to 3.1.9, the library's safe_join function fails to sanitize Windows reserved device names containing an empty NTFS Alternate Data Stream (ADS) marker (such as NUL:). This allows remote, unauthenticated attackers to trigger indefinite thread-blocking operations on Windows hosts, resulting in application-wide resource exhaustion.

Alon Barad
Alon Barad
10 views•7 min read
•about 6 hours ago•CVE-2026-103921
7.4

CVE-2026-103921: TLS Certificate Validation Bypass in @graphql-tools/executor-legacy-ws

A vulnerability in @graphql-tools/executor-legacy-ws prior to version 1.1.35 hardcodes the TLS rejectUnauthorized setting to false for outgoing secure WebSocket (wss://) connections. This defect allows unauthenticated remote attackers to perform Adversary-in-the-Middle (MitM) attacks, capturing or tampering with sensitive connection payloads and subscription data.

Alon Barad
Alon Barad
10 views•6 min read