MediumVulnerability
CVE-2026-105748: Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI…
- Source
- NVD(opens in a new tab)
- Identifier
- CVE-2026-105748
- Published
- Record updated
Summary
Docling versions 2.16.0 through 2.131.0 contain a flaw in the InputFormat.JSON_DOCLING backend (docling/backend/json/docling_json_backend.py). It accepts serialized DoclingDocument input without rejecting picture image references that point to local paths or file URIs. When the document is exported with ImageRefMode.EMBEDDED, the DoclingDocument._with_embedded_pictures and ImageRef.pil_image methods open those references, so readable image bytes can appear in Markdown or HTML output, limited to files Pillow can decode as images. Differing decode behavior can also reveal whether a path exists. Direct untrusted loading through docling-core is outside this fix.
Mitigation
Fixed in 2.131.0.
Related items
- HighGHSA-6wjp-v33h-5cvq: PraisonAI: AgentOS defaults to network-exposed no-auth mode, allowing unauthenticated agent invocation and instruction disclosureSimilar attack · GitHub Advisory Database
- HighCVE-2026-101998: Docker Sandboxes could fail open while masking credentials in protected proxy responses. When a response-body read…Similar attack · NVD/CVE Database
- MediumEncrypted instructions trick Copilot CLI into spilling developer secretsSimilar attack · CSO Online
- HighCVE-2026-93677: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due…Similar attack · NVD/CVE Database
- HighCVE-2026-101331: IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due…Similar attack · NVD/CVE Database