Sceawere
Vulnerability Detail
CVE-2026-105748UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Docling Arbitrary Local File Read
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 1h ago
- Vendor
- docling-project
- Product
- docling
- Attack Type
- CWE-73: External Control of File Name or Path
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.16.0 until 2.131.0, the InputFormat.JSON_DOCLING backend in docling/backend/json/docling_json_backend.py validates serialized DoclingDocument input without rejecting picture image references that contain local paths or file URIs. When the document is enriched or exported with ImageRefMode.EMBEDDED, the DoclingDocument._with_embedded_pictures and ImageRef.pil_image methods can open those references and place readable image bytes in Markdown or HTML output. Disclosure is limited to files Pillow can decode as images, while differing decode behavior can also reveal whether a path exists. Direct untrusted loading through docling-core is outside this Docling fix. This issue is fixed in 2.131.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-05T22:16:57.793Z",
"pubdate": "2026-10-05T22:16:57.793Z",
"executiveSummary": "The Docling document processing library is susceptible to an arbitrary local file read vulnerability due to improper validation of image references within serialized DoclingDocument objects.\nThis vulnerability affects versions 2.16.0 through 2.130.0 of the InputFormat.JSON_DOCLING backend.\nThe issue arises because the system fails to restrict image references to trusted sources, allowing attackers to specify local file paths or file URIs.\nWhen a maliciously crafted document is processed and exported using ImageRefMode.EMBEDDED, the library attempts to resolve these paths.\nSuccessful exploitation allows an attacker to exfiltrate the contents of local files that the application process has permission to access, provided the files can be decoded by the Pillow library.\nBeyond data exfiltration, the system's differential error handling during the decoding process can be leveraged as an oracle to confirm the existence of arbitrary files on the host filesystem.\nThis vulnerability represents a significant security risk in environments where untrusted Docling documents are parsed or enriched, potentially leading to unauthorized information disclosure.",
"technicalDetails": "The vulnerability is located in the docling/backend/json/docling_json_backend.py component, specifically within the handling of the InputFormat.JSON_DOCLING backend.\nThe root cause is a failure in the input validation logic, which does not sanitize or restrict image URI references to prevent the inclusion of local filesystem paths or file protocols.\nDuring the processing of a DoclingDocument, the methods DoclingDocument._with_embedded_pictures and ImageRef.pil_image are invoked when ImageRefMode.EMBEDDED is requested. These methods do not implement an allow-list or sandbox mechanism to validate the resource location, causing the library to treat local file system paths as valid image sources.\nThe attack flow commences when an attacker provides a maliciously crafted Docling JSON document containing image reference nodes that point to sensitive local files (e.g., /etc/passwd or configuration files) instead of valid remote or embedded image data.\nUpon ingestion, the Docling backend deserializes the document. When the enrichment or export process triggers the embedding of these pictures, the underlying Pillow library attempts to open the attacker-supplied file paths.\nIf the target file is a format recognizable by Pillow, the binary content is read, processed, and subsequently injected into the resulting Markdown or HTML output, effectively exfiltrating the file content to the user.\nIn scenarios where the target file is not a valid image format, the error messaging or processing delay during the decoding attempt provides an attacker with a side-channel to determine the presence or absence of specific files on the server (a local file existence oracle).\nThis vulnerability is restricted to environments where the Docling process is permitted by the OS to access the target file paths. Exploitation does not require authentication to the Docling library itself, as it is a logic error in the data processing layer. The exposure is largely dictated by the context in which Docling is deployed and the nature of the input source providing the serialized JSON documents."
}