Improper Plugin Management in Docling Affects Document Processing Capabilities
CVE-2026-105745

6.7MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105745?

In the Docling document processing tool, an improper management of plugin imports can lead to execution of potentially malicious code at startup. Versions 2.27.0 through 2.130.0 are affected, as an oversight allows all plugins to be imported even when external plugins are meant to be disabled. This vulnerability could permit malicious third-party packages to execute code without being detected, posing a significant risk to users. The issue has been addressed in version 2.131.0.

Affected Version(s)

docling >= 2.27.0, < 2.131.0

docling-slim >= 2.27.0, < 2.131.0

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.