CVE-2026-105748: Local File Inclusion and Arbitrary File Disclosure in Docling Document Parser
Vulnerability ID: CVE-2026-105748
CVSS Score: 4.3
Published: 2026-10-07
A Local File Inclusion (LFI) and Arbitrary File Disclosure vulnerability exists in Docling and Docling Slim versions >= 2.16.0 up to 2.131.0. When parsing serialized DoclingDocument structures using the JSON input format, the backend fails to restrict image URI schemes, allowing remote attackers to retrieve local files and verify path existence on the host system during embedded document export.
TL;DR
Docling is vulnerable to Local File Inclusion via crafted JSON inputs, allowing attackers to read local system images or verify file existence.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-73 (External Control of File Name or Path)
- Attack Vector: Network
- CVSS Score: 4.3 (Medium)
- EPSS Score: 0.00218
- Impact: Low Confidentiality (Local File Inclusion / Path Probing)
- Exploit Status: PoC / Non-weaponized
- KEV Status: Not Listed
Affected Systems
- docling-project/docling
- docling-project/docling-slim
-
docling: >= 2.16.0, < 2.131.0 (Fixed in:
2.131.0) -
docling-slim: >= 2.16.0, < 2.131.0 (Fixed in:
2.131.0)
Code Analysis
Commit: d4bb776
Clear local image references during JSON document parsing unless enable_local_fetch is explicitly configured.
Mitigation Strategies
- Upgrade docling to version 2.131.0 or higher.
- Ensure docling-core is upgraded to version 2.98.0 or higher.
- Avoid processing untrusted JSON documents if immediate patching is not possible.
- Implement strict schema validation at the application boundaries before passing documents to docling-core.
Remediation Steps:
- Modify your dependency configuration (e.g. pyproject.toml or requirements.txt) to require docling>=2.131.0.
- Deploy the updated container or environment to production.
- Ensure that enable_local_fetch is disabled (default behavior) in all backend option configurations.
References
- GitHub Security Advisory
- Official Fix Commit
- Official Pull Request
- Release Notes (v2.131.0)
- National Vulnerability Database (NVD)
Read the full report for CVE-2026-105748 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)