Local File Inclusion Vulnerability in Docling by Docling Project
CVE-2026-105751
6.9MEDIUM
What is CVE-2026-105751?
A local file inclusion vulnerability has been identified in Docling, affecting versions from 2.107.0 to 2.120.3. The issue arises from the way the application processes the xlink:href attribute in draw:image elements. When a referenced part is not located in the document archive, the application proceeds to utilize the xlink:href value as a filesystem path without proper security checks. This oversight allows attacker-controlled paths to be read, exposing readable files that can be decoded as images by Pillow. Additionally, the vulnerability could reveal other existing paths based on the attempt to read specified files. This issue has been resolved in version 2.120.3.
Affected Version(s)
docling >= 2.107.0, < 2.120.3
