HighVulnerability
CVE-2026-105744: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105744
- Published
- Record updated
Summary
Docling, a document processing library, versions 2.94.0 through 2.132.0 are affected when callers opt into LatexBackendOptions(tikz_engine="tectonic"). The Tectonic engine in docling/backend/latex/engines/tectonic.py compiles untrusted TikZ and preamble input without restricting TeX file primitives such as \openin and \openout. Crafted input can read files available to the converter and create or overwrite writable files, and enabling tikz_engine_allow_shell_escape additionally permits shell commands. The default configuration is not affected.
Mitigation
Fixed in 2.132.0.
Related items
- CriticalCVE-2026-108263: Astron Agent is an agentic workflow platform for building and running AI agents. Prior to 1.1.2, the default workflow coSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading
- HighGHSA-cv3g-hj65-pcfh: PraisonAI: Shell command allowlist bypass via find -exec built-in actionSimilar attack · GitHub Advisory Database
- CriticalGHSA-9mp3-24cc-77mg: PraisonAI: AICoder Arbitrary File Write and Command Execution via LLM Tool CallsSimilar attack · GitHub Advisory Database