Local File Inclusion Vulnerability in Docling Document Processing Tool
CVE-2026-105750
5.9MEDIUM
What is CVE-2026-105750?
A local file inclusion vulnerability exists in the Docling document processing tool, affecting versions from 2.82.0 to 2.118.1. The issue arises due to HTMLBackendOptions(render_page=True) allowing file URLs without proper verification. This can lead to the exposure of local text files through crafted HTML when the Playwright library is utilized. Affected configurations do not restrict local requests, thereby enabling the embedding of unintended local content within browser-rendered pages. The vulnerability is resolved in the update to version 2.118.1.
Affected Version(s)
docling >= 2.82.0, < 2.118.1
docling-slim >= 2.92.0, < 2.118.1
