Local File Inclusion Vulnerability in Docling Document Processing Tool
CVE-2026-105750

5.9MEDIUM

Key Information:

Vendor
CVE Published:
5 October 2026

What is CVE-2026-105750?

A local file inclusion vulnerability exists in the Docling document processing tool, affecting versions from 2.82.0 to 2.118.1. The issue arises due to HTMLBackendOptions(render_page=True) allowing file URLs without proper verification. This can lead to the exposure of local text files through crafted HTML when the Playwright library is utilized. Affected configurations do not restrict local requests, thereby enabling the embedding of unintended local content within browser-rendered pages. The vulnerability is resolved in the update to version 2.118.1.

Affected Version(s)

docling >= 2.82.0, < 2.118.1

docling-slim >= 2.92.0, < 2.118.1

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.