Sceawere
Vulnerability Detail
CVE-2026-105745UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Docling Arbitrary Plugin Execution Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.7
- Creation Date
- 1h ago
- Vendor
- docling-project
- Product
- docling
- Attack Type
- CWE-696: Incorrect Behavior Order
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.27.0 until 2.131.0, Docling plugin factories in docling/models/factories/base_factory.py call load_setuptools_entrypoints() before applying the allow_external_plugins setting, so every module registered in the Docling entry-point group is imported even when external plugins are disabled. An installed third-party or compromised package can therefore execute import-time code when Docling starts, while the subsequent namespace filter misleadingly reports that the plugin was not loaded. This issue is fixed in 2.131.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.7",
"pubDate": "2026-10-05T22:16:57.330Z",
"pubdate": "2026-10-05T22:16:57.330Z",
"executiveSummary": "Docling is vulnerable to an arbitrary code execution flaw due to improper handling of entry-point loading. The vulnerability resides in the way plugin factories process external modules during initialization. Specifically, Docling invokes load_setuptools_entrypoints() prior to enforcing the allow_external_plugins configuration setting. This allows malicious or compromised third-party packages installed in the local environment to execute arbitrary code at import-time, regardless of the intended security policy.\nThe vulnerability affects Docling versions 2.27.0 through 2.130.0. The risk is significant because the application assumes that external plugins are restricted based on configuration settings, yet the underlying mechanism loads these modules into the Python interpreter before the filter is applied. This creates a disconnect between the security configuration and the actual runtime behavior, potentially leading to unauthorized system access, data exfiltration, or persistence. Successful exploitation requires an attacker to introduce a malicious package into the Python environment, which is then automatically triggered by the initialization of Docling.",
"technicalDetails": "The root cause of this vulnerability is a sequence-of-operations error within the docling/models/factories/base_factory.py module. During the factory initialization, the load_setuptools_entrypoints() function is called to discover and register plugins defined via setuptools entry points. In the vulnerable versions (2.27.0 to 2.130.0), this discovery process occurs before the validation check that inspects the allow_external_plugins setting.\nIn Python, the mechanism of loading entry points involves importing the target module to resolve the associated factory or class reference. Because this import occurs during the entry-point discovery phase, any code present at the top level of a malicious or compromised package's entry point is executed immediately by the Python interpreter when load_setuptools_entrypoints() is invoked. This happens globally, rendering any subsequent filtering or conditional checks intended to suppress or ignore external plugins effectively useless, as the arbitrary code execution has already transpired.\nThe attack flow follows a predictable pattern: 1) An attacker ensures a malicious Python package is installed in the environment where Docling is utilized. 2) The package registers itself as an entry point within the Docling-specific namespace. 3) Upon initialization of the Docling library, load_setuptools_entrypoints() scans the installed packages and attempts to load the malicious entry point. 4) The Python interpreter executes the top-level import code of the malicious module. 5) Even if the Docling logic subsequently evaluates allow_external_plugins and determines that the plugin should not be used, the malicious payload has already successfully executed with the privileges of the process running Docling.\nThis vulnerability highlights a bypass of intended configuration security. The impact is significant as it grants attackers execution context at the start of the document processing pipeline. Because this occurs at import time, it bypasses standard application-layer authentication and authorization checks. There is no requirement for specific user interaction beyond the invocation of Docling. The vulnerability was identified and resolved by reordering the logic in version 2.131.0, ensuring that configuration-based restrictions are applied prior to the invocation of the entry-point discovery mechanism."
}