Sceawere

Vulnerability Detail

CVE-2026-105750UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Docling Local File Read Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.9
Creation Date
1h ago
Vendor
docling-project
Product
docling
Attack Type
CWE-552: Files or Directories Accessible to External Parties
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.82.0 until 2.118.1, HTMLBackendOptions(render_page=True) permits file URLs because HTMLDocumentBackend._get_browser_request_block_reason does not enforce the enable_local_fetch setting or confine local requests to the source document directory. Crafted path-backed HTML can embed a readable local text file in a browser-rendered page image when Playwright is installed. Only filesystem Path inputs are affected because stream inputs use an opaque origin, and the default configuration, command-line interface, docling-serve, and non-rendering backends are not affected. This issue is fixed in 2.118.1.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.9",
  "pubDate": "2026-10-05T22:16:58.097Z",
  "pubdate": "2026-10-05T22:16:58.097Z",
  "executiveSummary": "Docling versions 2.82.0 through 2.118.0 are susceptible to an arbitrary local file read vulnerability originating from insecure configuration handling within the HTMLDocumentBackend component.\nThe vulnerability occurs when processing HTML documents via the HTMLBackendOptions(render_page=True) configuration while Playwright is installed.\nBy crafting a malicious HTML file containing specific path-backed resource references, an attacker can coerce the rendering engine to access and embed sensitive local system files into the generated document output.\nThis vulnerability is restricted to filesystem path inputs, as stream inputs utilize an opaque origin that inherently mitigates this specific attack vector.\nThe impact includes the potential unauthorized disclosure of local files readable by the user process executing Docling.\nExploitation requires the victim to process a maliciously crafted document, making this a client-side or server-side document processing risk depending on the implementation context.\nThe vulnerability is fixed in version 2.118.1, which enforces proper origin validation and directory confinement for browser-based requests.",
  "technicalDetails": "The vulnerability resides within the HTMLDocumentBackend._get_browser_request_block_reason method, which fails to correctly validate or restrict local file access when the rendering engine (Playwright) is invoked via HTMLBackendOptions(render_page=True).\nIn affected versions, the logic fails to enforce the intended enable_local_fetch configuration policy. Furthermore, the backend lacks sufficient directory-level sandboxing, allowing the rendering engine to resolve absolute or relative path references that traverse outside the source document's directory.\nWhen a user provides a filesystem path to Docling, the HTML rendering process attempts to resolve resources defined within the HTML content. An attacker can exploit this by embedding references to arbitrary sensitive files (e.g., /etc/passwd or configuration files) using file:// URI schemes or direct path traversal strings.\nBecause the renderer is configured with render_page=True, the engine processes these external references as legitimate document assets. Consequently, the renderer reads the contents of the targeted local file and embeds it into the resulting document's visual representation (page image).\nThe attack flow proceeds as follows: First, the attacker creates a malicious HTML document containing an <img> or <iframe> tag that points to a target local file path. Second, this file is submitted to an application using a vulnerable version of Docling that processes filesystem inputs. Third, the HTMLDocumentBackend, failing to verify the request origin or destination, passes the file path to the Playwright renderer. Finally, the rendering engine treats the local file as a legitimate image or frame source, renders its content into the document's output, and returns the processed document to the user, effectively exfiltrating the local file content.\nThis vulnerability is not present in non-rendering backends, the command-line interface, or deployments using docling-serve, provided they do not trigger the vulnerable rendering path. Additionally, stream inputs are protected because they do not have a defined filesystem origin, preventing the renderer from resolving local file system paths via the standard resolution mechanisms."
}
CVE-2026-105750: Docling Local File Read Vulnerability (MEDIUM Severity, CVSS: 5.9) | Sceawere