Sceawere
Vulnerability Detail
CVE-2026-105744UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Docling Arbitrary File Access Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1h ago
- Vendor
- docling-project
- Product
- docling
- Attack Type
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.94.0 until 2.132.0, callers that opt into LatexBackendOptions(tikz_engine="tectonic") invoke docling/backend/latex/engines/tectonic.py to compile an untrusted TikZ body and document preamble without restricting TeX file primitives including \openin and \openout. Crafted input can read files available to the converter and create or overwrite writable files, and enabling the tikz_engine_allow_shell_escape option additionally permits shell commands through TeX. The default configuration, which does not enable Tectonic rendering, is not affected. This vulnerability is fixed in 2.132.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-05T22:16:57.177Z",
"pubdate": "2026-10-05T22:16:57.177Z",
"executiveSummary": "Docling versions 2.94.0 through 2.131.0 are susceptible to an arbitrary file read and write vulnerability stemming from insecure handling of TeX primitives within the Tectonic backend.\nThe vulnerability arises when callers explicitly enable 'LatexBackendOptions(tikz_engine=\"tectonic\")', allowing an attacker to supply a malicious TikZ body and document preamble.\nBecause the Tectonic backend fails to restrict TeX primitives like \\openin and \\openout, an attacker can read sensitive files from the host filesystem or overwrite existing writable files.\nFurthermore, if the 'tikz_engine_allow_shell_escape' option is enabled, the vulnerability escalates to arbitrary shell command execution.\nThe default configuration, which does not utilize the Tectonic backend, remains unaffected.\nSuccessful exploitation requires the processing of untrusted input through the vulnerable conversion pipeline, potentially leading to unauthorized data exfiltration or system compromise depending on the process permissions.",
"technicalDetails": "The vulnerability resides within docling/backend/latex/engines/tectonic.py. The root cause is the insufficient sandboxing of the Tectonic TeX engine execution environment when processing user-provided TikZ and LaTeX content.\nIn the affected versions (2.94.0 to 2.131.0), the conversion pipeline processes LaTeX/TikZ input without sanitizing or restricting access to dangerous TeX primitives. Specifically, the engine does not prevent the use of \\openin and \\openout commands. When an attacker provides a document containing these primitives, the Tectonic engine executes them with the privileges of the Docling process. This allows an attacker to bypass intended file access restrictions to read arbitrary files from the filesystem or overwrite files that the process user has write permissions for.\nThe exploitation flow is as follows: 1) An attacker submits a malicious document or data payload designed to be processed by Docling. 2) The caller of the library must have configured the conversion pipeline using LatexBackendOptions with 'tikz_engine' set to 'tectonic'. 3) The Docling backend passes this unsanitized input directly to the Tectonic engine. 4) The Tectonic engine interprets the embedded TeX primitives, executing file system operations (read/write) based on the attacker's instructions. 5) If 'tikz_engine_allow_shell_escape' is set to True, the attacker can use LaTeX commands that trigger shell execution, leading to Remote Code Execution (RCE).\nThis vulnerability is particularly impactful because it allows for both data exfiltration (via file reads) and system tampering (via file writes/shell execution). No special authentication is required by the library itself to trigger the vulnerability, as it is an inherent weakness in the configuration/execution logic of the component when processing untrusted input. The exposure is limited to systems that utilize the Tectonic rendering engine for document processing and is mitigated by the fact that it is not the default behavior of the product."
}