MediumVulnerability
CVE-2026-105751: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105751
- Published
- Record updated
Summary
Docling versions 2.107.0 through 2.120.3 are affected by CVE-2026-105751 in docling/backend/opendocument_backend.py. When an xlink:href value on a draw:image element points to a part missing from the archive, the _image_ref_from_odf_image function reads it as a filesystem path with no scheme check, no extraction-directory confinement, and no enable_local_fetch check. Readable image files are embedded in converted output, and other paths can be told apart through the read attempt.
Mitigation
Fixed in 2.120.3.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database