Skip to content
MediumVulnerability

CVE-2026-105750: Docling local file read through browser-rendered HTML page images

Identifier
CVE-2026-105750
Published
Record updated
View JSON
Affected
  • docling >= 2.82.0, < 2.118.1
  • docling-slim >= 2.92.0, < 2.118.1
Fixed in
2.118.1
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

Docling, a document processing library, versions 2.82.0 through 2.118.1 are affected by CVE-2026-105750. When HTMLBackendOptions(render_page=True) is used with Playwright installed, HTMLDocumentBackend._get_browser_request_block_reason fails to enforce enable_local_fetch or confine local requests to the source document directory, so file URLs are permitted. Crafted path-backed HTML can embed a readable local text file in a browser-rendered page image. Only filesystem Path inputs are affected; stream inputs, the default configuration, the command-line interface, docling-serve, and non-rendering backends are not.

Mitigation

Fixed in 2.118.1.