{"data":{"id":"ec2be969-ba55-48f4-b15e-52e3a8d377a1","title":"CVE-2026-105748: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…","summary":"Docling versions 2.16.0 through 2.131.0 contain a flaw in the InputFormat.JSON_DOCLING backend (docling/backend/json/docling_json_backend.py). It accepts serialized DoclingDocument input without rejecting picture image references that point to local paths or file URIs. When the document is exported with ImageRefMode.EMBEDDED, the DoclingDocument._with_embedded_pictures and ImageRef.pil_image methods open those references, so readable image bytes can appear in Markdown or HTML output, limited to files Pillow can decode as images. Differing decode behavior can also reveal whether a path exists. Direct untrusted loading through docling-core is outside this fix.","solution":"Fixed in 2.131.0.","labels":["security"],"sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-105748","publishedAt":"2026-10-05T22:16:57.793Z","cveId":"CVE-2026-105748","cweIds":["CWE-73","CWE-200"],"cvssScore":"4.3","cvssSeverity":"medium","severity":"medium","attackType":["data_extraction"],"issueType":"vulnerability","affectedPackages":["docling@>= 2.16.0, < 2.131.0 (fixed: 2.131.0)","docling-slim@>= 2.92.0, < 2.131.0 (fixed: 2.131.0)"],"affectedPackageNames":["docling","docling-slim"],"affectedVendors":[],"affectedVendorsRaw":["Docling"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"required","exploitMaturity":"unknown","epssScore":0.00222,"epssCheckedAt":"2026-10-10T02:58:27.768Z","kevDateAdded":null,"advisoryAliases":["GHSA-p944-4xh2-x776"],"affectedPackagesSource":"ghsa","affectedPackagesCheckedAt":"2026-10-10T03:42:53.042Z","patchAvailable":true,"disclosureDate":"2026-10-05T22:16:57.793Z","capecIds":["CAPEC-116"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.8,"researchCategory":null,"atlasIds":null}}